CVE-2024-0032
CVE-2024-0032 is a vulnerability in FileSystemProvider.java that allows unauthorized access to hidden directories. Due to improper input validation, a malicious actor could potentially escalate privileges locally if they can get a user to interact with a crafted request. SOCRadar's Vulnerability Risk Score (SVRS) for this CVE is 30, indicating a low level of active threat despite its presence "In The Wild". While the CVSS score of 6.5 suggests moderate severity, the low SVRS suggests limited real-world exploitability or active exploitation at this time. This vulnerability allows a local attacker to gain elevated access but requires user interaction to be exploited, reducing the overall risk. Organizations should still investigate and patch, especially given the potential for privilege escalation but can prioritize higher-risk vulnerabilities first. The main risk comes from an attacker already having some level of access to the system and the ability to trick a user.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.