CVE-2024-4230

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Dec 19, 2024
CWE ID 129

Summary

CVE-2024-4230 is a newly disclosed vulnerability affecting Edgecross Basic Software for Windows versions 1.00 and later, as well as Edgecross Basic Software for Developers versions 1.00 and later. This External Control of File Name or Path vulnerability enables a malicious local attacker to manipulate file names or paths, leading to potential information disclosure, data tampering, deletion, or even a Denial-of-Service (DoS) condition. By exploiting this vulnerability, an attacker could execute arbitrary malicious code, posing a significant risk to affected systems. Users are advised to apply patches or updates as soon as they become available to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share