CVE-2023-24930: Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2023-Mar
Released
2023-03-14
EPSS Score
1.15% (percentile: 78.5%)

FAQ

What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated to be able to exploit this vulnerability. How do I get the update for OneDrive for Mac? Tap the Settings Icon Tap the iTunes & App Store Turn on AUTOMATIC DOWNLOADS for Apps Alternatively Tap the App Store Icon Scroll down to find Microsoft OneDrive Tap the Update button

Affected Products (1)

Microsoft Office

  • OneDrive for MacOS Installer

Acknowledgments

<a href="https://github.com/kohnakagawa">Koh M. Nakagawa</a> with <a href="https://www.ffri.jp/en/index.htm">FFRI Security, Inc.</a>

Revision History

  • 2023-03-14: Information published.