2024-04-07 02:03:21 +00:00

28 lines
1021 B
JSON

{
"id": "CVE-2024-27674",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-04-03T17:15:55.710",
"lastModified": "2024-04-03T17:24:18.150",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "Macro Expert through 4.9.4 allows BUILTIN\\Users:(OI)(CI)(M) access to the \"%PROGRAMFILES(X86)%\\GrassSoft\\Macro Expert\" folder and thus an unprivileged user can escalate to SYSTEM by replacing the MacroService.exe binary."
},
{
"lang": "es",
"value": "Macro Expert hasta 4.9.4 permite a BUILTIN\\Users:(OI)(CI)(M) acceder a la carpeta \"%PROGRAMFILES(X86)%\\GrassSoft\\Macro Expert\" y, por lo tanto, un usuario sin privilegios puede escalar a SYSTEM reemplazando MacroService.exe binario."
}
],
"metrics": {},
"references": [
{
"url": "https://github.com/Alaatk/CVE-2024-27674/tree/main",
"source": "cve@mitre.org"
},
{
"url": "https://www.macro-expert.com/",
"source": "cve@mitre.org"
}
]
}