Msrc Microsoft Defender For Endpoint For Android vulnerabilities
2 known vulnerabilities affecting msrc/microsoft_defender_for_endpoint_for_android.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2024-49057HIGHCVSS 8.12024-12-10
CVE-2024-49057 [HIGH] CWE-20 Microsoft Defender for Endpoint on Android Spoofing Vulnerability
Microsoft Defender for Endpoint on Android Spoofing Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user must install and use a specially-crafted malicious application on their Android device.
Microsoft Defender for Endpoint: Microsoft Defender for Endpoint
Microsoft: Microsoft
Customer Action Required: Yes
Impac
msrc
CVE-2024-5535CRITICALCVSS 9.12024-11-12
CVE-2024-5535 [CRITICAL] CWE-1395 OpenSSL: CVE-2024-5535 SSL_select_next_proto buffer overread
OpenSSL: CVE-2024-5535 SSL_select_next_proto buffer overread
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2024-5535
Description: We are republishing this OpenSSL CVE to document that the latest version Microsoft Defender for Endpoint has been updated to protect against this OpenSSL library vulnerability.
FAQ: How could an attacker exploit this vulnerability?
Exploitation of this vulnerabil
msrc