Skip to main content

Evernote Releases Security Update

Evernote has released a security update to address a cross-site scripting (XSS) vulnerability in their Evernote for Windows desktop client. A local attacker could exploit this vulnerability to execute JavaScript commands on an affected device.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Evernote has released a security update to address a cross-site scripting (XSS) vulnerability in their Evernote for Windows desktop client. A local attacker could exploit this vulnerability to execute JavaScript commands on an affected device.

Affected platforms

The following platforms are known to be affected:

Evernote for Windows

  • Evernote for Windows - Versions prior to 6.16.1

Threat details

For further information:


Remediation steps

Type Step
Users and administrators are encouraged to review Evernote's security releases page and apply the necessary update.

CVE Vulnerabilities

Last edited: 17 February 2020 12:42 pm