CVE-2024-49056

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 302

Summary

CVE-2024-49056 is a newly disclosed vulnerability affecting airlift.microsoft.com. This issue permits an attacker, who already has network access with authorized credentials, to bypass authentication checks. The vulnerability lies in the assumption that certain data is immutable, which an adversary can exploit to elevate privileges, potentially leading to significant security implications. Microsoft is encouraged to release a patch as soon as possible to mitigate this risk. Until then, organizations are advised to strengthen their access control policies and monitor their networks closely.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share