External Control of File Name or Path (CWE-73)
A vulnerability in Windows Compressed Folder feature allows for tampering. This is classified as a Windows Compressed Folder Tampering Vulnerability. The vulnerability is associated with CWE-73: External Control of File Name or Path. It affects Windows 11 version 22H2 (up to but not including version 10.0.22621.3880) and Windows 11 version 23H2 (up to but not including version 10.0.22631.3880).
This vulnerability has a high impact on integrity but no impact on confidentiality or availability. It requires user interaction and can be exploited over a network. The attack complexity is low, and no privileges are required to execute the attack. The overall base CVSS score is 6.5, indicating a medium severity level. Successful exploitation could allow an attacker to manipulate file paths or names, potentially leading to unauthorized file access or execution.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available. Microsoft released updates to address this vulnerability on August 13, 2024. Users should apply the latest security updates for Windows 11 version 22H2 (to version 10.0.22621.3880 or later) and Windows 11 version 23H2 (to version 10.0.22631.3880 or later).
To mitigate this vulnerability: 1. Apply the latest security updates from Microsoft for affected Windows 11 versions. 2. Implement the principle of least privilege to limit the potential impact of exploitation. 3. Educate users about the risks of interacting with untrusted compressed folders or files from unknown sources. 4. Consider implementing additional security controls to monitor and restrict file system operations, especially those involving compressed folders. 5. Regularly review and update security policies related to file handling and user permissions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
A CVSS base score of 6.5 has been assigned.
Feedly found the first article mentioning CVE-2024-38165. See article
NVD published the first details for CVE-2024-38165
Feedly estimated the CVSS score as HIGH
EPSS Score was set to: 0.07% (Percentile: 33%)