CVE-2024-31498: High severity Yubico YubiKey Manager GUI vulnerability
Published Apr 4, 2024
·Updated
Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windows can open as Administrator.
Affected Software
1 affected component
Yubico YubiKey Manager GUI<1.2.6
Event History
Apr 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31498?
CVE-2024-31498 is considered a high-severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2024-31498?
To mitigate CVE-2024-31498, users should upgrade YubiKey Manager GUI to version 1.2.6 or later.
3
What versions of YubiKey Manager GUI are affected by CVE-2024-31498?
CVE-2024-31498 affects YubiKey Manager GUI versions prior to 1.2.6.
4
What type of vulnerability is CVE-2024-31498?
CVE-2024-31498 is a privilege escalation vulnerability that can be exploited when certain conditions are met.
5
Which platform is impacted by CVE-2024-31498?
CVE-2024-31498 specifically impacts the Windows platform when using the YubiKey Manager GUI.