MSRC compact vulnerability detail

CVE-2024-21390 · Microsoft Authenticator Elevation of Privilege Vulnerability

No description was published by MSRC.

Severity
Important
Impact
Elevation of Privilege
CVSS
7.1 base · 6.2 temporal
Release
2024-03-12
Signals
Microsoft Authenticator Elevation of Privilege Exploited: No Publicly disclosed: No Exploitability: Exploitation Less Likely
CWE
Patch Diff
Loading module diff metadata...
Resolved binary override
Use this when the MSRC module name cannot be mapped automatically or the resolved binary looks wrong.
Old version New version
Description
No description was published by MSRC.
FAQ / Articles
FAQ
According to the CVSS metric, Attack Vector is Local (AV:L). What does that mean for this vulnerability? An attacker would have to have local presence on the device through malware or a malicious application to be able to exploit this vulnerability.
FAQ
According to the CVSS metric, User Interaction is Required (UI:R). What interaction would the user have to do? The victim will have to close and re-open the Authenticator app for the attacker to exploit this vulnerability.
FAQ
According to the CVSS metric, Confidentiality and Integrity impact are High and Availability is None (C:H, I:H, A:N). What does that mean for this vulnerability? Exploitation of this vulnerability could allow an attacker to gain access to multi-factor authentication codes for the victim's accounts, as well as modify or delete accounts in the authenticator app but not prevent the app from launching or running.