CVE-2021-36666

HIGH

Druva Insync Client < 7.0.0 - Untrusted Search Path

Title source: rule
STIX 2.1

Description

An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 15.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (1)
druva/insync_client < 7.0.0
Published Jul 12, 2022
Tracked Since Feb 18, 2026