Evernote.Embedded.Link.Directory.Traversal

description-logoDescription

This indicates an attack attempt to exploit a Directory Traversal Vulnerability in Evernote for Mac.
A remote attacker could exploit this vulnerability by enticing a user into importing a maliciously crafted ENEX file and clicking on an embedded link. Successful exploitation could result in execution of an arbitrary program under the security context of the application.

affected-products-logoAffected Products

Evernote for Mac 7.x prior to 7.9.1

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://evernote.com/security/updates

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-06-13 14.632 Default_action:pass:drop
2019-05-30 14.623