CVE-2024-35260: Microsoft Dataverse Remote Code Execution Vulnerability
Published Jun 27, 2024
·Updated
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
Other sources
Microsoft Dataverse Remote Code Execution Vulnerability
— Microsoft
Affected Software
2 affected components
Microsoft Power Platform
Microsoft Power Platform
Event History
Jun 27, 2024
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:32 PM
Data Sourced
via MITRE·05:32 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35260?
CVE-2024-35260 is classified as a critical vulnerability due to its potential for remote code execution.
2
How can I fix CVE-2024-35260?
To fix CVE-2024-35260, apply the latest security updates provided by Microsoft for the affected software.
3
Who is affected by CVE-2024-35260?
CVE-2024-35260 affects users of Microsoft Dataverse within the Power Platform.
4
What type of vulnerability is CVE-2024-35260?
CVE-2024-35260 is an untrusted search path vulnerability that allows code execution over a network.
5
What should I do if I believe I am affected by CVE-2024-35260?
If you believe you are affected by CVE-2024-35260, immediately review your security posture and apply the necessary updates.