VDB
CVE-2024-35260
CVE-2024-35260
PUBLISHED
CVSS 8 HIGH
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
EPSS 6.86% · 91.5th percentile
Risk Scores
CVSS v3.1
8
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
6.86%
91.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Power Platform | N/A |
| microsoft | power_platform | N/A |
Timeline
- Jun 11, 2024 CVE Published
- Jun 27, 2024 CVE Updated
- Jun 28, 2024 EPSS Score
- Jul 20, 2024 EPSS Score
- Sep 3, 2024 EPSS Score
- Sep 26, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 18, 2024 EPSS Score
- Dec 3, 2024 EPSS Score
- Dec 25, 2024 EPSS Score
- Jan 16, 2025 EPSS Score
- Feb 8, 2025 EPSS Score