Lucene search

K
cvelistMicrosoftCVELIST:CVE-2024-28907
HistoryApr 09, 2024 - 5:01 p.m.

CVE-2024-28907 Microsoft Brokering File System Elevation of Privilege Vulnerability

2024-04-0917:01:11
CWE-59
microsoft
www.cve.org
cve-2024-28907
microsoft
brokering
file system
elevation of privilege
vulnerability

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C

8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

CNA Affected

[
  {
    "vendor": "Microsoft",
    "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
    "cpes": [
      "cpe:2.3:o:microsoft:windows_server_23h2:10.0.25398.830:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "x64-based Systems"
    ],
    "versions": [
      {
        "version": "10.0.0",
        "lessThan": "10.0.25398.830",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  }
]

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C

8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%