PT-2024-2288 · Microsoft · Windows

Chen Qingyang

+2

·

Published

2024-03-12

·

Updated

2024-12-27

·

CVE-2024-21435

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows (affected versions not specified)
Description The issue is related to an uncontrolled search path element in the Windows OLE mechanism. It allows a remote attacker to execute arbitrary code. There is no information about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Untrusted Search Path

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2024-02222
CVE-2024-21435

Affected Products

Windows