CVE-2024-49051 is an Elevation of Privilege vulnerability affecting Microsoft PC Manager. This vulnerability has a CVSS score of 7.8 (HIGH), indicating that a local attacker with low privileges can achieve high impact on confidentiality, integrity, and availability without user interaction. While not currently in CISA's KEV catalog, there is no public exploit code available, though it has received some community and media attention, including a mention in Microsoft's November 2024 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.14.10.0CPE matchmatch criteria | cpe:2.3:a:microsoft:pc_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.