Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.
The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information.
Link | Tags |
---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49071 | vendor advisory |