9.8
CVE-2024-49147
- EPSS 0.59%
- Veröffentlicht 12.12.2024 19:15:13
- Zuletzt bearbeitet 10.01.2025 18:09:53
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Microsoft Update Catalog Elevation of Privilege Vulnerability
Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Update Catalog Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.59% | 0.693 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| secure@microsoft.com | 9.3 | 3.9 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.