CVE-2024-30073

Sept. 10, 2024, 5:43 p.m.

Awaiting Analysis
CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

Products

Windows Operating System

Source

secure@microsoft.com

Tags

CVE-2024-30073 details

Published : Sept. 10, 2024, 5:15 p.m.
Last Modified : Sept. 10, 2024, 5:43 p.m.

Description

Windows Security Zone Mapping Security Feature Bypass Vulnerability

CVSS Score

1 2 3 4 5 6 7.8 8 9 10

Weakness

Weakness Name Description
CWE-41 Improper Resolution of Path Equivalence The product is vulnerable to file system contents disclosure through path equivalence. Path equivalence involves the use of special characters in file and directory names. The associated manipulations are intended to generate multiple names for the same object.

CVSS Data

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

7.8

Exploitability Score

1.8

Impact Score

5.9

Base Severity

HIGH

This website uses the NVD API, but is not approved or certified by it.