QID 378074

Date Published: 2023-03-15

QID 378074: Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability

Microsoft OneDrive keeps files backed up, protected with 2FA, synced, and accessible on all your devices, allowing you and your team to collaborate at any given time

CVE-2023-24930 Updated build 23.020.0125.0002

QID Detection Logic (Authenticated) :
This checks for vulnerable version of OneDrive

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 3.6 severity.
  • Solution
    Vendor has released fix to address these vulnerabilities. Refer to CVE-2023-24930

    CVEs related to QID 378074

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-24930 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24930