Evernote Releases Security Update
Evernote has released a security update to address a cross-site scripting (XSS) vulnerability in their Evernote for Windows desktop client. A local attacker could exploit this vulnerability to execute JavaScript commands on an affected device.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Evernote has released a security update to address a cross-site scripting (XSS) vulnerability in their Evernote for Windows desktop client. A local attacker could exploit this vulnerability to execute JavaScript commands on an affected device.
Affected platforms
The following platforms are known to be affected:
Evernote for Windows
- Evernote for Windows - Versions prior to 6.16.1
Threat details
For further information:
Remediation steps
| Type | Step |
|---|---|
|
Users and administrators are encouraged to review Evernote's security releases page and apply the necessary update. |
CVE Vulnerabilities
Last edited: 17 February 2020 12:42 pm