CVE-2024-39755

A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged operation. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
Configurations

No configuration.

History

18 Dec 2024, 15:15

Type Values Removed Values Added
Summary (en) A privilege escalation vulnerability exists in the Veertu Anka Build 1.42.0. The vulnerability occurs during Anka node agent update. A low privilege user can trigger the update action which can result in unexpected elevation of privilege. (en) A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged operation. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

21 Nov 2024, 09:28

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2060 -

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de escalada de privilegios en Veertu Anka Build 1.42.0. La vulnerabilidad ocurre durante la actualización del agente del nodo Anka. Un usuario con pocos privilegios puede activar la acción de actualización, lo que puede provocar una elevación inesperada de privilegios.

03 Oct 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-03 16:15

Updated : 2024-12-18 15:15


NVD link : CVE-2024-39755

Mitre link : CVE-2024-39755

CVE.ORG link : CVE-2024-39755


JSON object : View

Products Affected

No product.

CWE
CWE-282

Improper Ownership Management