CVE-2024-49147 is a critical deserialization of untrusted data vulnerability affecting the Microsoft Update Catalog, allowing an unauthorized attacker to elevate privileges on the webserver. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB) or KEV entry, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community. Its EPSS score is low, suggesting a lower probability of exploitation in the wild compared to most CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:update_catalog:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.