7.8

CVE-2024-21315

Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftDefender For Endpoint SwPlatformwindows Version < 10.0.25398.531
MicrosoftDefender For Endpoint SwPlatformwindows Version < 10.0.19045.3693
   MicrosoftWindows 10 22h2 Version- HwPlatformarm64
   MicrosoftWindows 10 22h2 Version- HwPlatformx64
MicrosoftDefender For Endpoint SwPlatformwindows Version < 10.0.22621.2715
   MicrosoftWindows 11 22h2 Version- HwPlatformarm64
   MicrosoftWindows 11 23h2 Version- HwPlatformarm64
MicrosoftDefender For Endpoint SwPlatformwindows Version < 6.3.9600.21813
   MicrosoftWindows Server 2012 Versionr2
MicrosoftDefender For Endpoint SwPlatformwindows Version < 10.0.14393.6452
   MicrosoftWindows 10 1607 Version- HwPlatformx64
   MicrosoftWindows 10 1607 Version- HwPlatformx86
   MicrosoftWindows Server 2016 Version-
MicrosoftDefender For Endpoint SwPlatformwindows Version < 6.2.9200.24710
   MicrosoftWindows Server 2012 Version-
MicrosoftDefender For Endpoint SwPlatformwindows Version < 10.0.19045.3693
   MicrosoftWindows 10 22h2 Version- HwPlatformx86
MicrosoftDefender For Endpoint SwPlatformwindows Version < 10.0.22621.2715
   MicrosoftWindows 11 22h2 Version- HwPlatformx64
   MicrosoftWindows 11 23h2 Version- HwPlatformx64
MicrosoftDefender For Endpoint SwPlatformwindows Version < 10.0.10240.20308
   MicrosoftWindows 10 1507 Version- HwPlatformx64
   MicrosoftWindows 10 1507 Version- HwPlatformx86
MicrosoftDefender For Endpoint SwPlatformwindows Version < 10.0.19043.3693
   MicrosoftWindows 10 21h2 Version- HwPlatformarm64
   MicrosoftWindows 10 21h2 Version- HwPlatformx64
   MicrosoftWindows 10 21h2 Version- HwPlatformx86
MicrosoftDefender For Endpoint SwPlatformwindows Version < 10.0.22000.2600
   MicrosoftWindows 11 21h2 Version- HwPlatformarm64
   MicrosoftWindows 11 21h2 Version- HwPlatformx64
MicrosoftDefender For Endpoint SwPlatformwindows Version < 6.2.9200.24569
   MicrosoftWindows Server 2022 Version-
MicrosoftDefender For Endpoint SwPlatformwindows Version < 10.0.20348.2113
   MicrosoftWindows Server 2022 Version-
MicrosoftDefender For Endpoint SwPlatformwindows Version < 10.0.17763.5122
   MicrosoftWindows 10 1809 Version- HwPlatformarm64
   MicrosoftWindows 10 1809 Version- HwPlatformx64
   MicrosoftWindows 10 1809 Version- HwPlatformx86
   MicrosoftWindows Server 2019 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.505
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
secure@microsoft.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.