Local Privilege Escalation Vulnerability Affects MongoDB Servers
CVE-2024-7553

7.8HIGH

Key Information:

Vendor
MongoDB
Status
Vendor
CVE Published:
7 August 2024

Summary

A vulnerability exists in MongoDB Server software that arises from improper validation of files loaded from local untrusted directories on Windows operating systems. This weakness could allow for local privilege escalation, leading to the execution of arbitrary actions based on the content of untrusted files. Specifically, MongoDB Server versions prior to specified releases as well as the MongoDB C and PHP Drivers are impacted. To mitigate potential risks, users are advised to upgrade to the latest versions of affected products.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.