PT-2024-26074 · M Files · My Files

Khilli

·

Published

2024-09-03

·

Updated

2024-09-05

·

CVE-2024-34654

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions My Files versions prior to SMR Sep-2024 Release 1
Description The issue concerns an improper export of an android application component in My Files, allowing local attackers to access files with the privilege of My Files. This enables unauthorized access to sensitive data.
Recommendations For versions prior to SMR Sep-2024 Release 1, update to SMR Sep-2024 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2024-34654

Affected Products

My Files