CVE-2024-20692
5.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.1 / Impact: 3.6
Source: NVD
Description
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Affected (16)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.10240.20402 | |
| Before 10.0.14393.6614 | |
| Before 10.0.17763.5329 | |
| Before 10.0.19044.3930 | |
| Before 10.0.19045.3930 | |
| Before 10.0.22000.2713 | |
| Before 10.0.22621.3007 | |
| Before 10.0.22631.3007 | |
| All versions | |
| All versions | |
| Before 10.0.14393.6614 | |
| Before 10.0.17763.5329 | |
| Before 10.0.20348.2227 | |
| Before 10.0.25398.643 |
Related CWEs
CWE-326
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
References (2)
Source: secure@microsoft.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.