CVE-2024-21390: Microsoft Authenticator Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 7.1)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2024-Mar
Released
2024-03-12
EPSS Score
1.10% (percentile: 78.1%)

FAQ

According to the CVSS metric, Attack Vector is Local (AV:L). What does that mean for this vulnerability? An attacker would have to have local presence on the device through malware or a malicious application to be able to exploit this vulnerability. According to the CVSS metric, User Interaction is Required (UI:R). What interaction would the user have to do? The victim will have to close and re-open the Authenticator app for the attacker to exploit this vulnerability. According to the CVSS metric, Confidentiality and Integrity impact are High and Availability is None (C:H, I:H, A:N). What does that mean for this vulnerability? Exploitation of this vulnerability could allow an attacker to gain access to multi-factor authentication codes for the victim's accounts, as well as modify or delete accounts in the authenticator app but not prevent the app from launching or running.

Affected Products (1)

Apps

  • Microsoft Authenticator

Security Updates (1)

Acknowledgments

Anonymous, alirez, Anonymous

Revision History

  • 2024-03-12: Information published.