VDB
CVE-2024-35260
CVE-2024-35260
PUBLISHED
CVSS 8 HIGH
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
EPSS 0.82% · 54.3th percentile
Risk Scores
CVSS 3.1
8
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
0.82%
54.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Power Platform | N/A, N/A |
| microsoft | power_platform | N/A, N/A |
Timeline
- Jun 11, 2024 CVE Published
- Jun 28, 2024 EPSS Score
- Jul 21, 2024 EPSS Score
- Sep 4, 2024 EPSS Score
- Sep 26, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 19, 2024 EPSS Score
- Dec 4, 2024 EPSS Score
- Dec 26, 2024 EPSS Score
- Jan 9, 2025 PoC Published
- Jan 18, 2025 EPSS Score
- Mar 4, 2025 EPSS Score