CVE-2024-4229 is an Incorrect Default Permissions vulnerability affecting Edgecross Basic Software for Windows and Edgecross Basic Software for Developers, versions 1.00 and later. This flaw allows a local attacker to execute arbitrary malicious code, leading to information disclosure, data tampering or deletion, or a denial-of-service condition, provided the software is installed in a non-restricted directory. The vulnerability carries a high CVSS score of 7.8, indicating a significant risk. Its attack vector is local, but attack complexity is high, and it can result in complete compromise of confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Edgecross Consortium | Edgecross Basic Software For Developers | versions 1.00 and laterCNA affecteddefault unaffected | |
| Edgecross Consortium | Edgecross Basic Software For Windows | versions 1.00 and laterCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.