Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability
Microsoft · Windows
Date added (CISA)
2024-08-05
Remediation due
2024-08-26
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.