← back
CVE-2023-24890mediumCWE-1390

Microsoft OneDrive for iOS Security Feature Bypass Vulnerability

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 1.2%
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
In short

Microsoft OneDrive for iOS contains a security feature bypass vulnerability that allows attackers to circumvent protective measures. This flaw could enable unauthorized access to protected content on affected devices.

Technical detail

The vulnerability permits bypassing security features in OneDrive for iOS through CWE-1390 (Improper Restriction of Rendered UI Layers or Frames). An attacker with local access or ability to interact with the device UI can circumvent authentication or authorization mechanisms, potentially accessing sensitive data stored or synchronized through the application.

Summary generated and translated by AI from the official description.
Microsoft OneDrive for iOS Security Feature Bypass Vulnerability
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C