CVE-2023-24930 is an Elevation of Privilege vulnerability affecting Microsoft OneDrive for macOS. With a CVSS score of 7.8 (High), it allows a local attacker to achieve high impact to confidentiality, integrity, and availability with low attack complexity and no user interaction required. While not currently listed in CISA's KEV catalog, there is no public exploit code available, and community discussion and media coverage are minimal, suggesting limited active exploitation or widespread awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 22.0.0.0, < 23.020.0125.0002CPE matchmatch criteria | cpe:2.3:a:microsoft:onedrive:*:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.