CVE-2024-35260

An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:power_platform:-:*:*:*:*:*:*:*

History

03 Feb 2025, 15:15

Type Values Removed Values Added
CPE cpe:2.3:a:microsoft:power_platform:-:*:*:*:*:*:*:*
First Time Microsoft
Microsoft power Platform
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35260 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35260 - Vendor Advisory

28 Dec 2024, 00:15

Type Values Removed Values Added
Summary An authenticated attacker can exploit an Untrusted Search Path vulnerability in Microsoft Dataverse to execute code over a network. An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
CVSS v2 : unknown
v3 : 8.0
v2 : unknown
v3 : unknown

28 Jun 2024, 23:15

Type Values Removed Values Added
Summary Microsoft Dataverse Remote Code Execution Vulnerability An authenticated attacker can exploit an Untrusted Search Path vulnerability in Microsoft Dataverse to execute code over a network.

27 Jun 2024, 19:25

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-27 18:15

Updated : 2025-02-03 15:15


NVD link : CVE-2024-35260

Mitre link : CVE-2024-35260


JSON object : View

Products Affected

microsoft

  • power_platform
CWE

No CWE.