CVE-2024-34474: High severity Clario Clario vulnerability
Published May 5, 2024
·Updated
Clario through 2024-04-11 for Desktop has weak permissions for %PROGRAMDATA%\Clario and tries to load DLLs from there as SYSTEM.
Affected Software
1 affected component
Clario Clario<=2024-04-11
Event History
May 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34474?
CVE-2024-34474 is classified as a high severity vulnerability due to its potential exploitation by attackers.
2
How do I fix CVE-2024-34474?
To fix CVE-2024-34474, users should update to the latest version of Clario released after April 11, 2024.
3
What are the potential impacts of CVE-2024-34474?
The potential impacts of CVE-2024-34474 include unauthorized access and execution of malicious code by loading insecure DLLs.
4
Who is affected by CVE-2024-34474?
CVE-2024-34474 affects users of Clario Desktop software versions up to and including 2024-04-11.
5
Is CVE-2024-34474 a local or remote vulnerability?
CVE-2024-34474 is considered a local vulnerability since it requires local access to the affected system to exploit.