PT-2024-33182 · Unknown · Officeweb365

Peiqi0

·

Published

2024-11-19

·

Updated

2024-11-20

·

CVE-2024-48694

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OfficeWeb365 versions 7.18.23.0 through 8.6.1.0
Description The issue allows a remote attacker to execute arbitrary code via the "pw/savedraw" component. This enables the attacker to upload files that can lead to code execution, potentially compromising the system.
Recommendations For versions 7.18.23.0 through 8.6.1.0, consider disabling the "pw/savedraw" component to prevent file upload and subsequent code execution until a patch is available. Restrict access to the file upload functionality in the affected versions to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-48694

Affected Products

Officeweb365