{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/nitroshare-desktop--0.3.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-66050"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NitroShare Desktop \u003c= 0.3.4"],"_cs_severities":["high"],"_cs_tags":["path-traversal","persistence","code-execution","vulnerability"],"_cs_type":"advisory","_cs_vendors":["NitroShare"],"content_html":"\u003cp\u003eA significant path traversal vulnerability, tracked as CVE-2026-66050, affects NitroShare Desktop versions through 0.3.4. The flaw resides within the application's LAN file transfer server, allowing unauthenticated attackers operating on the same local network to exploit a lack of path validation. By crafting a malicious filename that includes directory traversal sequences within the JSON item header name field, an attacker can write arbitrary files to locations outside the intended transfer root directory. This means that if the current user has write permissions to a sensitive directory, such as the Windows Startup folder, an attacker can place a malicious executable there. Upon the next user login or system restart, this executable will be automatically executed, granting the attacker persistent code execution on the compromised system. This vulnerability poses a high risk due to its unauthenticated nature and potential for persistent compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker, located on the same local area network (LAN) as a victim running NitroShare Desktop, identifies the vulnerable service.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a specially designed filename payload containing directory traversal sequences (e.g., \u003ccode\u003e../../../../ProgramData/Microsoft/Windows/Start Menu/Programs/Startup/malicious.exe\u003c/code\u003e) within the JSON item header.\u003c/li\u003e\n\u003cli\u003eThis malicious filename and the accompanying file payload are sent to the NitroShare LAN file transfer server as part of a file transfer request.\u003c/li\u003e\n\u003cli\u003eDue to the path traversal vulnerability (CVE-2026-66050), the NitroShare server fails to properly validate the path.\u003c/li\u003e\n\u003cli\u003eNitroShare writes the incoming file payload to the arbitrary path specified by the attacker, such as the Windows Startup folder.\u003c/li\u003e\n\u003cli\u003eUpon the next user logon or system reboot, the malicious executable placed in the Startup folder is automatically executed by the operating system.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves persistent code execution on the victim's system, allowing for further compromise or control.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-66050 allows an unauthenticated attacker on the same local network to achieve persistent code execution on a vulnerable Windows system. The primary impact is the ability to write arbitrary files to any location the NitroShare service's user context has write access. This can be leveraged to place malicious executables in critical system startup locations, such as the Windows Startup folder (e.g., \u003ccode\u003eC:\\Users\\\u0026lt;username\u0026gt;\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\u003c/code\u003e or \u003ccode\u003eC:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\u003c/code\u003e), ensuring the malware runs every time the user logs in. This grants the attacker a durable foothold, enabling further attacks such as data exfiltration, lateral movement, or ransomware deployment, without requiring user interaction beyond the initial network presence.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-66050 immediately by updating NitroShare Desktop to a version past 0.3.4 once available.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-66050 Exploitation - File Write to Startup Folder\u0026quot; to your SIEM to detect suspicious file writes to critical persistence locations.\u003c/li\u003e\n\u003cli\u003eMonitor \u003ccode\u003efile_event\u003c/code\u003e logs for suspicious file creations or modifications within Windows Startup directories (e.g., \u003ccode\u003eC:\\Users\\\u0026lt;username\u0026gt;\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to restrict access to the LAN file transfer service, limiting the attack surface for unauthenticated attackers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-27T15:18:54Z","date_published":"2026-07-27T15:18:54Z","id":"https://feed.craftedsignal.io/briefs/2026-07-nitroshare-path-traversal/","summary":"NitroShare Desktop versions up to and including 0.3.4 are vulnerable to a path traversal flaw in their LAN file transfer server, allowing unauthenticated attackers on the same network to craft malicious filenames containing directory traversal sequences within the JSON item header. Exploiting this, attackers can write arbitrary files outside the intended transfer root to any location the current user has write access, including the Windows Startup folder, leading to persistent code execution upon user login.","title":"Path Traversal Vulnerability in NitroShare Desktop (CVE-2026-66050)","url":"https://feed.craftedsignal.io/briefs/2026-07-nitroshare-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - NitroShare Desktop \u003c= 0.3.4","version":"https://jsonfeed.org/version/1.1"}