CVE-2024-46462
Last modified
CVE-2024-46462 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZEDMAIL has to be modified to prevent this vulnerability.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZEDMAIL has to be modified to prevent this vulnerability.
Metrics
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-46462?
How severe is CVE-2024-46462?
How do I fix CVE-2024-46462?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-46451TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overf…9.8
- CVE-2024-46452A Host Header injection vulnerability in the password reset …6.1
- CVE-2024-46453A cross-site scripting (XSS) vulnerability in the component …6.1
- CVE-2024-46455unstructured v.0.14.2 and before is vulnerable to XML Extern…9.8
- CVE-2024-4646A vulnerability was found in Campcodes Complete Web-Based Sc…6.1
- CVE-2024-46461VLC media player 3.0.20 and earlier is vulnerable to denial …8
- CVE-2024-46463By default, dedicated folders of ORIZON for Windows up to 20…7.8
- CVE-2024-46464In PRIMX ZED Enterprise up to 2024.3, technical files stored…7.8
- CVE-2024-46465By default, dedicated folders of CRYHOD for Windows up to 20…7.8
- CVE-2024-46466By default, dedicated folders of ZONECENTRAL for Windows up …7.8
- CVE-2024-46467By default, dedicated folders of ZONEPOINT for Windows up to…7.8
- CVE-2024-46468A Server-Side Request Forgery (SSRF) vulnerability exists in…7.5
Are you affected by CVE-2024-46462?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
