CVE-2024-4229

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Dec 19, 2024

Summary

CVE-2024-4229 is a newly disclosed vulnerability affecting Edgecross Basic Software for Windows versions 1.00 and later, as well as Edgecross Basic Software for Developers versions 1.00 and later. This Incorrect Default Permissions issue allows a malicious local attacker to execute arbitrary malicious code if the product is installed in a folder other than one restricted to administrative users. The exploitation of this vulnerability could result in information disclosure, modification, deletion, or a denial-of-service condition. Attackers can take advantage of this flaw to gain unauthorized access and manipulate the software, potentially causing significant damage.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share