CVE-2024-35253 describes an Elevation of Privilege vulnerability in Microsoft Azure File Sync. With a CVSS score of 4.4 (Medium), this vulnerability requires local access, high attack complexity, and user interaction to achieve high integrity impact, but no confidentiality or availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, with only one mention and one media article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.0.0.0, < 17.3.0.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_file_sync:*:*:*:*:*:*:*:* | ||
18.0.0.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_file_sync:18.0.0.0:*:*:*:*:*:*:* | ||
>= 16.0.0, < 17.3CPE match | cpe:2.3:a:microsoft:azure_file_sync:*:*:*:*:*:*:*:* | ||
>= 17.0.0, < 17.3CPE match | cpe:2.3:a:microsoft:azure_file_sync:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 18.1CPE match | cpe:2.3:a:microsoft:azure_file_sync:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.