PT-2024-2254 · Microsoft · Intune Linux Agent

Xenos

·

Published

2024-03-12

·

Updated

2024-12-06

·

CVE-2024-26201

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Intune Linux Agent (affected versions not specified)
Description The issue is related to insufficient access restrictions in the Microsoft Intune Linux agent, which is used for managing access to corporate applications, data, and resources. Exploitation of this issue may allow an attacker to elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-02187
CVE-2024-26201

Affected Products

Intune Linux Agent