CVE-2023-24904
published 2023-05-09CVE-2023-24904: Windows Installer Elevation of Privilege Vulnerability
PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.62%
45.8th percentile
Windows Installer Elevation of Privilege Vulnerability
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26519 | 6.1.7601.26519 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.22070 | 6.0.6003.22070 |
| msrc | windows_server_2008_for_32-bit_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_x64-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_r2_for_x64-based_systems_service_pack_1 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wpwh-m3q4-99f6: Windows Installer Elevation of Privilege Vulnerability
ghsa_unreviewed·2023-05-09
CVE-2023-24904 [HIGH] GHSA-wpwh-m3q4-99f6: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
Microsoft
Windows Installer Elevation of Privilege Vulnerability
vendor_msrc·2023-05-09·CVSS 7.1
CVE-2023-24904 [HIGH] CWE-59 Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker would only be able to delete targeted files on a system. They would not gain privileges to view or modify file contents.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to no loss of confidentiality (C:N) but have major impact on integrity (I:H) and on availability (A:H). What does that mean for this vulnerability?
This vulnerability does not allow disclosure of any confidential information, but could allow an attacker to delete data that could include data that results in the service being unavailable.
Windows Installer: Windows Installer
Microsoft: Microsoft
Customer Action Re
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-09
Published