Link following in Microsoft 365 Apps for Enterprise - CVE-2024-26199

 

Link following in Microsoft 365 Apps for Enterprise - CVE-2024-26199

Published: March 12, 2024 / Updated: March 14, 2024


Vulnerability identifier: #VU87462
CSH Severity: Low
CVSS v4 BT: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-26199
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insecure link following within the Office Performance Monitor executable. A local user can create a symbolic link to a critical file on the system and delete arbitrary files.

Successful exploitation of the vulnerability may allow arbitrary code execution with elevated privileges.


Affected software

Microsoft 365 Apps for Enterprise

How to mitigate CVE-2024-26199

Install updates from vendor's website.

Microsoft 365 Apps for Enterprise - addressed in versions 16.0.16130.20928, 16.0.16731.20600, 16.0.17126.20216, 16.0.17231.20290, 16.0.17328.20184

External References

Related Security Bulletins