CVE-2024-46467
Last modified
CVE-2024-46467 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONEPOINT has to be modified to prevent this vulnerability.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONEPOINT has to be modified to prevent this vulnerability.
Metrics
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-46467?
How severe is CVE-2024-46467?
How do I fix CVE-2024-46467?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-46461VLC media player 3.0.20 and earlier is vulnerable to denial …8
- CVE-2024-46462By default, dedicated folders of ZEDMAIL for Windows up to 2…7.8
- CVE-2024-46463By default, dedicated folders of ORIZON for Windows up to 20…7.8
- CVE-2024-46464In PRIMX ZED Enterprise up to 2024.3, technical files stored…7.8
- CVE-2024-46465By default, dedicated folders of CRYHOD for Windows up to 20…7.8
- CVE-2024-46466By default, dedicated folders of ZONECENTRAL for Windows up …7.8
- CVE-2024-46468A Server-Side Request Forgery (SSRF) vulnerability exists in…7.5
- CVE-2024-4647A vulnerability was found in Campcodes Complete Web-Based Sc…6.1
- CVE-2024-46470Cross Site Scripting vulnerability in CodeAstro Membership M…6.1
- CVE-2024-46471The Directory Listing in /uploads/ Folder in CodeAstro Membe…7.5
- CVE-2024-46472CodeAstro Membership Management System 1.0 is vulnerable to …8.6
- CVE-2024-46475A reflected cross-site scripting (XSS) vulnerability on the …4.8
Are you affected by CVE-2024-46467?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
