Remote Code Execution Vulnerability Affects Power Automate Desktop
CVE-2024-43479
8.5HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 10 September 2024
Summary
A vulnerability has been identified in Microsoft Power Automate Desktop that allows remote code execution. This issue arises from insufficient input validation mechanisms, enabling an attacker to execute arbitrary code on the affected system. Successful exploitation could lead to unauthorized access, posing significant risks to data integrity and confidentiality. Microsoft has provided guidance for remediation, and users are encouraged to apply the latest patches to mitigate potential threats.
Affected Version(s)
Power Automate for Desktop Unknown 1.0.0.0 < 2.47.119.24249
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved