CVE-2024-36074 is a remote code execution vulnerability affecting Netwrix CoSoSys Endpoint Protector through version 5.9.3 and CoSoSys Unify through version 7.0.6. An attacker with administrative access to the server can force a client to download and execute a malicious file. This vulnerability has a CVSS score of 7.2 (High), indicating high impact on confidentiality, integrity, and availability, with low attack complexity and no user interaction required. While no active exploits, public exploit code, or significant community discussion have been observed, the potential for severe impact warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.