CVE-2024-7553

Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue affects MongoDB Server v5.0 versions prior to 5.0.27, MongoDB Server v6.0 versions prior to 6.0.16, MongoDB Server v7.0 versions prior to 7.0.12, MongoDB Server v7.3 versions prior 7.3.3, MongoDB C Driver versions prior to 1.26.2 and MongoDB PHP Driver versions prior to 1.18.1. Required Configuration: Only environments with Windows as the underlying operating system is affected by this issue
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_2004:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_20h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h1:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_2004:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_20h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h1:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_21h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_22h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*
OR cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_2004:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_20h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h1:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_21h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_22h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:a:mongodb:php_driver:*:*:*:*:*:mongodb:*:*
OR cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_2004:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_20h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h1:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_21h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_22h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*

History

19 Sep 2024, 20:46

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 7.8
CPE cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_21h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_22h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:x64:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x64:*
cpe:2.3:a:mongodb:php_driver:*:*:*:*:*:mongodb:*:*
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_2004:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_20h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h1:-:*:*:*:*:*:x64:*
CWE NVD-CWE-noinfo
First Time Microsoft windows 10 1809
Microsoft windows 10 1909
Microsoft windows 10 1511
Mongodb mongodb
Microsoft
Microsoft windows 11 22h2
Microsoft windows 10 1507
Microsoft windows 10 2004
Microsoft windows 10 20h2
Microsoft windows Server 2022
Microsoft windows 10 21h2
Microsoft windows 11 23h2
Microsoft windows 10 22h2
Mongodb
Mongodb php Driver
Microsoft windows Server 2016
Microsoft windows 10 21h1
Microsoft windows Server 2019
Mongodb c Driver
Microsoft windows 10 1709
Microsoft windows 10 1703
Microsoft windows 10 1607
Microsoft windows 10 1803
Microsoft windows 11
Microsoft windows 11 21h2
Microsoft windows 10 1903
Summary
  • (es) La validación incorrecta de archivos cargados desde un directorio local no confiable puede permitir la escalada de privilegios locales si el sistema operativo subyacente es Windows. Esto puede provocar que la aplicación ejecute un comportamiento arbitrario determinado por el contenido de los archivos no confiables. Este problema afecta a las versiones de MongoDB Server v5.0 anteriores a la 5.0.27, MongoDB Server v6.0 anteriores a la 6.0.16, MongoDB Server v7.0 anteriores a la 7.0.12, MongoDB Server v7.3 anteriores a la 7.3.3, MongoDB C Driver anteriores a la 1.26.2 y MongoDB PHP Driver anteriores a la 1.18.1. Configuración requerida: este problema solo afecta a los entornos con Windows como sistema operativo subyacente.
References () https://jira.mongodb.org/browse/CDRIVER-5650 - () https://jira.mongodb.org/browse/CDRIVER-5650 - Vendor Advisory
References () https://jira.mongodb.org/browse/PHPC-2369 - () https://jira.mongodb.org/browse/PHPC-2369 - Vendor Advisory
References () https://jira.mongodb.org/browse/SERVER-93211 - () https://jira.mongodb.org/browse/SERVER-93211 - Vendor Advisory

07 Aug 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-07 10:15

Updated : 2024-09-19 20:46


NVD link : CVE-2024-7553

Mitre link : CVE-2024-7553

CVE.ORG link : CVE-2024-7553


JSON object : View

Products Affected

microsoft

  • windows_11_21h2
  • windows_server_2022
  • windows_11_22h2
  • windows_10_21h1
  • windows_10_22h2
  • windows_11_23h2
  • windows_10_20h2
  • windows_server_2019
  • windows_10_1703
  • windows_10_21h2
  • windows_10_1809
  • windows_10_1803
  • windows_server_2016
  • windows_10_1507
  • windows_10_2004
  • windows_10_1903
  • windows_10_1909
  • windows_10_1511
  • windows_10_1709
  • windows_11
  • windows_10_1607

mongodb

  • c_driver
  • mongodb
  • php_driver
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control