Executive brief
NAVER MYBOX Explorer is a Windows application used to manage and sync files with NAVER's cloud storage service. A security flaw in versions prior to 3.0.11.160 allows a person with limited access to a computer to gain full administrative control (SYSTEM privileges). This could allow an attacker to bypass security restrictions, access sensitive data from other users, or install malicious software on the affected machine.
Technical details
A privilege escalation vulnerability exists in NAVER MYBOX Explorer for Windows due to incorrect privilege assignment (CWE-266). The application fails to properly validate or restrict access to specific registry keys used by its service or background processes. A local attacker with low-level user privileges can manipulate these registry entries to redirect application execution or configuration. This allows the attacker to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. The issue is resolved in version 3.0.11.160.
Affected products
- NAVER MYBOX Explorer before 3.0.11.160
Timeline
- 2026-05-08: disclosed
- 2026-05-08: advisory
- 2026-05-11: other: NVD analysis initiated