2024-12-08 03:06:42 +00:00

60 lines
1.9 KiB
JSON

{
"id": "CVE-2024-46465",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-11-15T18:15:28.220",
"lastModified": "2024-11-25T20:15:08.760",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of CRYHOD has to be modified to prevent this vulnerability."
},
{
"lang": "es",
"value": "De forma predeterminada, otros usuarios pueden acceder a las carpetas dedicadas de CRYHOD para Windows hasta la versi\u00f3n 2024.3 para hacer un uso indebido de los archivos t\u00e9cnicos y obligarlos a realizar tareas con mayores privilegios. Es necesario modificar la configuraci\u00f3n de CRYHOD para evitar esta vulnerabilidad."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"attackVector": "LOCAL",
"attackComplexity": "HIGH",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 1.4,
"impactScore": 5.8
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-276"
}
]
}
],
"references": [
{
"url": "https://www.primx.eu/en/bulletins/security-bulletin-24932296/",
"source": "cve@mitre.org"
}
]
}