CVE-2024-46480
CVSS 3.1 Score 8.4 of 10 (high)
Details
Published Jan 13, 2025
CWE ID 522
Summary
CVE-2024-46480 is a newly disclosed vulnerability affecting Venki Supravizio BPM. This issue allows authenticated attackers, who possess Application Administrator access, to escalate their privileges and leak NTLM hashes on the underlying host system. By exploiting this vulnerability, attackers can potentially gain higher levels of access and compromise sensitive data or systems. This represents a significant risk for organizations using Venki Supravizio BPM and underscores the importance of applying the available patches or workarounds as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.