CVE-2024-7553
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue affects MongoDB Server v5.0 versions prior to 5.0.27, MongoDB Server v6.0 versions prior to 6.0.16, MongoDB Server v7.0 versions prior to 7.0.12, MongoDB Server v7.3 versions prior 7.3.3, MongoDB C Driver versions prior to 1.26.2 and MongoDB PHP Driver versions prior to 1.18.1. Required Configuration: Only environments with Windows as the underlying operating system is affected by this issue
Published:Aug 7, 2024
Last Modified:Sep 19, 2024
EPS:Aug 7, 2024
EPSS Score:0.00115
CVSS Score:7.3
Affected Products
Vendor
Product
Action
Vendor
Microsoft
Product
Windows 10 1507
Microsoft
Windows 10 1507
Vendor
Microsoft
Product
Windows 10 1511
Microsoft
Windows 10 1511
Vendor
Microsoft
Product
Windows 10 1607
Microsoft
Windows 10 1607
Vendor
Microsoft
Product
Windows 10 1703
Microsoft
Windows 10 1703
Vendor
Microsoft
Product
Windows 10 1709
Microsoft
Windows 10 1709
Vendor
Microsoft
Product
Windows 10 1803
Microsoft
Windows 10 1803
Vendor
Microsoft
Product
Windows 10 1809
Microsoft
Windows 10 1809
Vendor
Microsoft
Product
Windows 10 1903
Microsoft
Windows 10 1903
Vendor
Microsoft
Product
Windows 10 1909
Microsoft
Windows 10 1909
Vendor
Microsoft
Product
Windows 10 2004
Microsoft
Windows 10 2004
Vendor
Microsoft
Product
Windows 10 20h2
Microsoft
Windows 10 20h2
Vendor
Microsoft
Product
Windows 10 21h1
Microsoft
Windows 10 21h1
Vendor
Microsoft
Product
Windows 10 21h2
Microsoft
Windows 10 21h2
Vendor
Microsoft
Product
Windows 10 22h2
Microsoft
Windows 10 22h2
Vendor
Microsoft
Product
Windows 11
Microsoft
Windows 11
Vendor
Microsoft
Product
Windows 11 21h2
Microsoft
Windows 11 21h2
Vendor
Microsoft
Product
Windows 11 22h2
Microsoft
Windows 11 22h2
Vendor
Microsoft
Product
Windows 11 23h2
Microsoft
Windows 11 23h2
Vendor
Microsoft
Product
Windows Server 2016
Microsoft
Windows Server 2016
Vendor
Microsoft
Product
Windows Server 2019
Microsoft
Windows Server 2019
Vendor
Microsoft
Product
Windows Server 2022
Microsoft
Windows Server 2022
Vendor
Mongodb
Product
C Driver
Mongodb
C Driver
Vendor
Mongodb
Product
Mongodb
Mongodb
Mongodb
Vendor
Mongodb
Product
Php Driver
Mongodb
Php Driver
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
