CVE-2024-43612

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Oct 21, 2024
CWE ID 79

Summary

CVE-2024-43612 is a newly disclosed vulnerability affecting Power BI Report Server. Hackers can exploit this spoofing weakness to deceive users into believing they are interacting with legitimate reports, potentially leading to unintended actions or data disclosure. This issue could pose a significant risk to organizations that rely on Power BI for critical data analysis and decision-making, as it bypasses authentication controls and impersonates trusted reports. Microsoft is currently working on a patch to address this vulnerability and recommends users apply the fix as soon as it becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Power Bi Report Server

Affected Vendors

  • Microsoft