# CVE-2024-5924

## Summary

- **CVE ID:** CVE-2024-5924
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** CWE-693
- **Published:** Jun 13, 2024
- **Last Modified:** Mar 13, 2026

## Description

Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the handling of shared folders. When syncing files from a shared folder belonging to an untrusted account, the Dropbox desktop application does not apply the Mark-of-the-Web to the local files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-23991.

## Affected Products

- Dropbox — Dropbox Desktop (198.4.7615)

## References

- [CNA](https://www.zerodayinitiative.com/advisories/ZDI-24-677/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.25%
- **EPSS Percentile:** 67.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._