Improper Parsing Vulnerability in FileZ Client
CVE-2024-8058

7.6HIGH

Key Information:

Vendor

Lenovo

Vendor
CVE Published:
16 December 2024

What is CVE-2024-8058?

An improper parsing vulnerability exists in the FileZ Client, which may allow attackers to exploit crafted files within the FileZ directory. This flaw results from issues related to URL preloading, enabling potential unauthorized access to arbitrary files on the device. Users are urged to be aware of this security risk and implement necessary precautions to mitigate exposure.

Affected Version(s)

FileZ Client 0 < 9.8.6.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.