Executive brief
Mattermost Desktop App is a communication platform client used by organizations to access team messaging and collaboration features on Windows machines. Versions 5.8.0 and earlier fail to use absolute paths when searching for the Windows command shell (cmd.exe), allowing an attacker who can place a malicious cmd.exe file in a user's Downloads folder to execute arbitrary code with the user's privileges when the app launches.
Technical details
This vulnerability is a CWE-427 uncontrolled search path (DLL/binary hijacking) issue. The Mattermost Desktop App versions up to 5.8.0 search for cmd.exe without specifying an absolute path, causing Windows to search in predictable locations including the user's current working directory and Downloads folder. A local attacker with write access to a target user's Downloads folder can place a malicious cmd.exe binary that will be executed with the user's privileges when the application launches. The attack requires local file system access and user interaction (app launch), but no authentication. The vulnerability is fixed in version 5.9.0.
Affected products
- Mattermost Desktop App <=5.8.0
Timeline
- 2024-09-16: disclosed
- 2024-09-16: patched: Version 5.9.0 released