CVE-2024-4230
 
Severity Score
7.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-04-26 CVE Reserved
- 2024-12-19 CVE Published
- 2024-12-19 CVE Updated
- 2024-12-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-73: External Control of File Name or Path
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://jvn.jp/vu/JVNVU92857077/index.html | Government Resource |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Edgecross Consortium Search vendor "Edgecross Consortium" | Edgecross Basic Software For Windows Search vendor "Edgecross Consortium" for product "Edgecross Basic Software For Windows" | 1.00 Search vendor "Edgecross Consortium" for product "Edgecross Basic Software For Windows" and version "1.00" | en |
Affected
| ||||||
Edgecross Consortium Search vendor "Edgecross Consortium" | Edgecross Basic Software For Developers Search vendor "Edgecross Consortium" for product "Edgecross Basic Software For Developers" | 1.00 Search vendor "Edgecross Consortium" for product "Edgecross Basic Software For Developers" and version "1.00" | en |
Affected
|