CVE-2024-11969: Incorrect default permissions in Cradlepoint NetCloud Exchange
The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been identified that full control permissions exist on the ‘Everyone’ group (i.e. any user who has local access to the operating system regardless of their privileges).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11969?
CVE-2024-11969 is categorized as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2024-11969?
To mitigate CVE-2024-11969, ensure that proper file and folder permissions are set for the NetCloud Exchange client.
Who is affected by CVE-2024-11969?
CVE-2024-11969 affects users of the Cradlepoint NetCloud Exchange client for Windows, version 1.110.50.
What type of vulnerability is CVE-2024-11969?
CVE-2024-11969 is an insecure file and folder permissions vulnerability.
What are the potential impacts of CVE-2024-11969?
Exploitation of CVE-2024-11969 may allow a normal user to escalate privileges, execute arbitrary code, and maintain persistence on the system.