CVE-2023-24930Link Following in Microsoft Onedrive FOR Macos Installer

CWE-59Link Following3 documents3 sources
Severity
7.8HIGHNVD
EPSS
1.1%
top 21.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 14

Description

Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5microsoft/onedrive_for_macos_installer22.0.0.023.020.0125.0002
NVDmicrosoft/onedrive22.0.0.023.020.0125.0002

Patches

🔴Vulnerability Details

1
GHSA
GHSA-x7h3-27xg-26qm: Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability2023-03-14

📋Vendor Advisories

1
Microsoft
Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability2023-03-14