CVE-2024-46480

CVSS 3.1 Score 8.4 of 10 (high)

Details

Published Jan 13, 2025
CWE ID 522

Summary

CVE-2024-46480 is a newly disclosed vulnerability affecting Venki Supravizio BPM. This issue allows authenticated attackers, who possess Application Administrator access, to escalate their privileges and leak NTLM hashes on the underlying host system. By exploiting this vulnerability, attackers can potentially gain higher levels of access and compromise sensitive data or systems. This represents a significant risk for organizations using Venki Supravizio BPM and underscores the importance of applying the available patches or workarounds as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share