CVE Vulnerabilities

CVE-2024-49071

Improper Authorization of Index Containing Sensitive Information

Published: Dec 12, 2024 | Modified: Jan 10, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.

Weakness

The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information.

Affected Software

Name Vendor Start Version End Version
Defender_for_endpoint Microsoft - (including) - (including)

References