2024-12-08 03:06:42 +00:00

60 lines
2.0 KiB
JSON

{
"id": "CVE-2024-46467",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-11-15T18:15:28.377",
"lastModified": "2024-11-25T20:15:09.170",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONEPOINT has to be modified to prevent this vulnerability."
},
{
"lang": "es",
"value": "De forma predeterminada, otros usuarios pueden acceder a las carpetas dedicadas de ZONEPOINT para Windows hasta la versi\u00f3n 2024.1 para hacer un uso indebido de los archivos t\u00e9cnicos y obligarlos a realizar tareas con mayores privilegios. Es necesario modificar la configuraci\u00f3n de ZONEPOINT para evitar esta vulnerabilidad."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"attackVector": "LOCAL",
"attackComplexity": "HIGH",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 1.4,
"impactScore": 5.8
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-276"
}
]
}
],
"references": [
{
"url": "https://www.primx.eu/en/bulletins/security-bulletin-24932299/",
"source": "cve@mitre.org"
}
]
}