Site icon TheCyberThrone

MongoDB fixes High severity vulnerability CVE-2024-7553

Advertisements

MongoDB has released patches for a high-severity vulnerability affecting multiple versions of its server and driver products that could allow a malicious local user to escalate their privileges, potentially taking complete control.

The flaw, tracked as CVE-2024-7553 with a CVSS score of 7.3, stems from how MongoDB handles files loaded from untrusted local directories. This improper validation could allow an attacker to trick the database software into executing arbitrary code contained within these files. The potential impact is severe, as a successful exploit could give the attacker the same permissions as the system administrator.

Advertisements

The affected products are as follows

The patched versions include:

MongoDB Server:

MongoDB urges all users running the affected products on Windows environments to update to the latest patched versions immediately.

Exit mobile version