Unauthorized Privilege Elevation Vulnerability in GroupMe
CVE-2024-38164

9.6CRITICAL

Key Information:

Vendor
Microsoft
Status
Vendor
CVE Published:
23 July 2024

Summary

The vulnerability involves improper access control within GroupMe, enabling an unauthenticated attacker to escalate privileges over a network. This exploitation occurs when a user is manipulated into clicking a malicious link, thereby allowing unauthorized actions on their behalf. As the issue compromises user security, it is essential for users to be aware of potential phishing tactics and to ensure they maintain caution when engaging with unfamiliar links.

Affected Version(s)

GroupMe Unknown

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.