First published: Thu Dec 12 2024(Updated: )
<p>Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.</p>
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Update Catalog | ||
Microsoft Update Catalog |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49147 is considered a high-severity vulnerability due to its potential for privilege escalation.
To fix CVE-2024-49147, update your Microsoft Update Catalog to the latest version provided by Microsoft.
CVE-2024-49147 affects systems using Microsoft Update Catalog.
CVE-2024-49147 can be exploited by an unauthorized attacker to elevate privileges on the web server.
There is currently no official workaround for CVE-2024-49147, so it is recommended to apply the patch as soon as it is available.