CVE-2024-26185

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 12, 2024
Updated: Dec 27, 2024
CWE ID 73

Summary

CVE-2024-26185 is a newly disclosed vulnerability affecting Windows Compressed Folder functionality. Maliciously crafted compressed files can be manipulated, leading to unintended execution of code or data tampering. An attacker could exploit this vulnerability by supplying a specially crafted .zip or .cab file, potentially resulting in privileged access or data theft. Windows users are advised to update their systems with the latest Microsoft Security patch to mitigate this risk. In essence, CVE-2024-26185 represents a critical Windows Compressed Folder vulnerability, enabling attackers to tamper with compressed files and execute malicious code or manipulate data. This can be potentially exploited through specially crafted .zip or .cab files, posing a significant risk to Windows users. The vulnerability can lead to privileged access or data theft, and Microsoft recommends applying the latest security patches to address the issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 11 22h2
  • Microsoft Windows 11 23h2

Affected Vendors

  • Microsoft