CVE-2024-49147

Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:update_catalog:-:*:*:*:*:*:*:*

History

10 Jan 2025, 18:09

Type Values Removed Values Added
CPE cpe:2.3:a:microsoft:update_catalog:-:*:*:*:*:*:*:*
Summary
  • (es) La deserialización de datos no confiables en el Catálogo de Microsoft Update permite que un atacante no autorizado eleve privilegios en el servidor web del sitio web.
First Time Microsoft update Catalog
Microsoft
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49147 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49147 - Vendor Advisory

12 Dec 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-12 19:15

Updated : 2025-01-10 18:09


NVD link : CVE-2024-49147

Mitre link : CVE-2024-49147

CVE.ORG link : CVE-2024-49147


JSON object : View

Products Affected

microsoft

  • update_catalog
CWE
CWE-502

Deserialization of Untrusted Data