ZeroHour

CVE-2024-49147

CVSS 3.1
9.8 critical
EPSS
1%p69
Published
()
Modified
Description

Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.

Vendors
microsoft
Products
update catalog
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.