CVE-2024-23447
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-23447 is a vulnerability affecting the Windows Network Drive Connector. It arises when assigning permissions to a file using Document Level Security, with explicit allow write and deny read. Although the document remains inaccessible to the user in the Network Drive, it can still be searched and potentially identified by the user, posing a potential security risk. This issue may allow unauthorized users to gain insight into restricted files, potentially leading to data breaches or other malicious activities. Windows users are advised to apply relevant patches or updates to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.