Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2024-38177: Windows App Installer Spoofing Vulnerability

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?

The attacker must convince a user to call Windows App Installer with a specially crafted malicious winget file.

Microsoft Security Response Center
#vulnerability#windows#Windows App Installer#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2024-49060: Azure Stack HCI Elevation of Privilege Vulnerability