CVE-2024-49147

Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:update_catalog:-:*:*:*:*:*:*:*

History

10 Jan 2025, 18:09

Type Values Removed Values Added
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49147 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49147 - Vendor Advisory
Summary
  • (es) La deserialización de datos no confiables en el Catálogo de Microsoft Update permite que un atacante no autorizado eleve privilegios en el servidor web del sitio web.
First Time Microsoft update Catalog
Microsoft
CPE cpe:2.3:a:microsoft:update_catalog:-:*:*:*:*:*:*:*

12 Dec 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-12 19:15

Updated : 2025-01-10 18:09


NVD link : CVE-2024-49147

Mitre link : CVE-2024-49147

CVE.ORG link : CVE-2024-49147


JSON object : View

Products Affected

microsoft

  • update_catalog
CWE
CWE-502

Deserialization of Untrusted Data