CVE-2024-12903
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Dec 23, 2024
CWE ID 276
Summary
CVE-2024-12903 is a newly identified vulnerability affecting Evoko Home, version 2.4.2 to 2.7.4. This issue involves incorrect default permissions that allow non-admin users to exploit weak file and folder permissions. By taking advantage of these vulnerabilities, attackers can escalate privileges, execute arbitrary code, and maintain persistence on the compromised machine. Notably, full control permissions exist on the ‘Everyone’ group, making it easier for any local user, regardless of their privileges, to exploit this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.