PT-2024-31997 · Unknown · Zedmail For Windows

Nicolas Rodrigues

·

Published

2024-11-15

·

Updated

2024-11-25

·

CVE-2024-46462

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions ZEDMAIL for Windows versions up to 2024.3
Description The issue allows other users to access dedicated folders of ZEDMAIL for Windows by default, potentially misusing technical files and making them perform tasks with higher privileges.
Recommendations For versions up to 2024.3, modify the configuration of ZEDMAIL to prevent this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-46462

Affected Products

Zedmail For Windows