github cryptomator/cryptomator 1.12.4
1.12.4 (Windows Only)

one month ago

What's Changed

Security Fixes 🚨

  • Deletion of protected resources: The Cryptomator MSI installer is build with the WiX toolkit. Installers build with a toolkit version below 3.14.1 can be used to delete system directories by using directory junctions. (CVE-2024-29187)
  • Local Privilege Escalation: The Cryptomator EXE installer is build wiht the WiX toolkit. Installers build with a toolkit version below 3.14.1 can be used to execute arbitrary binaries by using the Windows temp directory. (CVE-2024-29188)

We advise to remove the vulnerable installers from the system. Already cached installers will be removed when installing this update.


Full Changelog: 1.12.3...1.12.4


💾 SHA-256 checksums of release artifacts:

c2a8442edff5e8355f5dad6600436f434e05d374d897643ca6bff32edabc5c38 .\Cryptomator-1.12.4-x64.exe
939809d8bd0e8a31be311bd390c0d70c00196e22c83493a085285d72460474f4 .\Cryptomator-1.12.4-x64.msi

As usual, the GPG signatures can be checked using our public key 5811 7AFA 1F85 B3EE C154 677D 615D 449F E6E6 A235.

Don't miss a new cryptomator release

NewReleases is sending notifications on new releases.