CVE-2024-36246

Missing authorization vulnerability exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be altered or deleted.
Configurations

No configuration.

History

08 Apr 2025, 05:15

Type Values Removed Values Added
References
  • () https://www.yrl.com/fwp_support/info/khvu7f00000007j8.html -
  • () https://www.yrl.com/fwp_support/info/khvu7f0000000auf.html -
Summary (en) Missing authorization vulnerability exists in Unifier and Unifier Cast Version.5.0 or later, and the patch "20240527" not applied. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be modified or deleted. (en) Missing authorization vulnerability exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be altered or deleted.

21 Nov 2024, 09:21

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN17680667/ - () https://jvn.jp/en/jp/JVN17680667/ -
References () https://www.yrl.com/fwp_support/info/khvu7f00000000q7.html - () https://www.yrl.com/fwp_support/info/khvu7f00000000q7.html -

15 Aug 2024, 17:35

Type Values Removed Values Added
CWE CWE-862
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Existe una vulnerabilidad de autorización faltante en Unifier y Unifier Cast versión 5.0 o posterior, y el parche "20240527" no se aplicó. Si se explota esta vulnerabilidad, se puede ejecutar código arbitrario con privilegios LocalSystem. Como resultado, se puede instalar un programa malicioso y se pueden modificar o eliminar datos.

31 May 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-31 06:15

Updated : 2025-04-08 05:15


NVD link : CVE-2024-36246

Mitre link : CVE-2024-36246

CVE.ORG link : CVE-2024-36246


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization