#VU87462 Link following in Microsoft 365 Apps for Enterprise - CVE-2024-26199
Published: March 12, 2024 / Updated: March 14, 2024
Microsoft 365 Apps for Enterprise
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure link following within the Office Performance Monitor executable. A local user can create a symbolic link to a critical file on the system and delete arbitrary files.
Successful exploitation of the vulnerability may allow arbitrary code execution with elevated privileges.