Jul 2024: GroupMe Elevation of Privilege Vulnerability
CVE-2024-38164 Published on July 23, 2024

GroupMe Elevation of Privilege Vulnerability
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.

Vendor Advisory NVD

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2024-38164 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2024-38164

Want to know whenever a new CVE is published for Microsoft Groupme? stack.watch will email you.

 

Affected Versions

Microsoft GroupMe Version - is affected by CVE-2024-38164

Exploit Probability

EPSS
3.92%
Percentile
88.10%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.