Microsoft Authenticator Elevation of Privilege VulnerabilityVendor advisory
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21390 CVE-2024-21390
HIGH
Microsoft Authenticator Elevation of Privilege Vulnerability
Record summary
CVE-2024-21390 has a selected CVSS score of 7.1 (high).
Description
Microsoft Authenticator Elevation of Privilege Vulnerability
Description source: GitHub Advisory
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 5, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 12, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Microsoft AuthenticatorBrowse Microsoft / Microsoft Authenticator | CVE List | 1.0.0 to < 6.2401.0617 | affected |
authenticatorBrowse Microsoft / authenticator | VulnCheck | Version data not supplied | |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-21390