We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6769

Medium to High Integrity Privilege Escalation in Microsoft Windows



AssignerFortra
Reserved2024-07-15
Published2024-09-26
Updated2024-10-02

Description

A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process to a high integrity process without the intervention of a UAC prompt.



HIGH: 8.4CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
MEDIUM: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-426 Untrusted Search Path

Product status

Default status
affected

10.0.0
affected

Default status
affected

10.0.0
affected

Default status
affected

10.0.0
affected

Default status
affected

10.0.0
affected

Default status
affected

10.0.0
affected

Credits

Ricardo Narvaja 0x400852a100

Nicolás Economou 0x400852a110

References

https://www.fortra.com/security/advisories/research/fr-2024-002

cve.org CVE-2024-6769

nvd.nist.gov CVE-2024-6769

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.