PT-2024-32000 · Unknown · Zonecentral For Windows

Nicolas Rodrigues

·

Published

2024-11-15

·

Updated

2024-11-25

·

CVE-2024-46466

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions ZONECENTRAL for Windows versions up to 2024.3 ZONECENTRAL for Windows versions up to Q.2021.2
Description The issue allows other users to access dedicated folders of ZONECENTRAL for Windows, potentially misusing technical files and making them perform tasks with higher privileges.
Recommendations For ZONECENTRAL for Windows versions up to 2024.3, modify the configuration to restrict access to dedicated folders. For ZONECENTRAL for Windows versions up to Q.2021.2, modify the configuration to restrict access to dedicated folders.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-46466

Affected Products

Zonecentral For Windows