Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2023-24890

Опубликовано: 14 мар. 2023
Источник: msrc
CVSS3: 6.5
EPSS Низкий

Описание

Microsoft OneDrive for iOS Security Feature Bypass Vulnerability

FAQ

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?

Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.

What kind of security feature could be bypassed by successfully exploiting this vulnerability?

An attacker who successfully exploited this vulnerability could gain access to files stored in a locked vault.

Does this vulnerability affect all OneDrive for iOS customers?

No. Only customers based in Australia are required to take action as the feature which was susceptible to this vulnerability was only deployed to that region.

Обновления

ПродуктСтатьяОбновление
OneDrive for iOS

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 78%
0.01168
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 3 года назад

Microsoft OneDrive for iOS Security Feature Bypass Vulnerability

CVSS3: 6.5
github
почти 3 года назад

Microsoft OneDrive for iOS Security Feature Bypass Vulnerability

CVSS3: 6.5
fstec
почти 3 года назад

Уязвимость службы размещения файлов OneDrive for iOS, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 78%
0.01168
Низкий

6.5 Medium

CVSS3