Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2024-38250

7.8HIGH

Key Information:

Summary

The Windows Graphics Component is subject to an elevation of privilege vulnerability, which could allow an attacker to execute arbitrary code with elevated privileges. Successfully exploiting this vulnerability requires that an attacker log onto the target system and run a specially crafted application. This vulnerability poses significant risks by enabling unauthorized access to sensitive system resources and functions, potentially leading to greater attacks on the affected Windows operating environments. It is crucial for users and organizations to remain vigilant and apply recommended patches to mitigate potential exploitation.

Affected Version(s)

Microsoft Office for Android Unknown 16.0.1 < 16.0.16827.2xxxxx

Microsoft Office for Universal Unknown 16.0.1 < 16.0.14326.21xxxx

Microsoft Office LTSC for Mac 2021 Unknown 16.0.1 < 16.89.24090815

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.