Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.114741
Category:Databases
Title:MongoDB Local Privilege Escalation Vulnerability (SERVER-93211)
Summary:MongoDB is prone to a local privilege escalation; vulnerability.
Description:Summary:
MongoDB is prone to a local privilege escalation
vulnerability.

Vulnerability Insight:
Incorrect validation of files loaded from a local untrusted
directory may allow local privilege escalation if the underlying operating systems is Windows.
This may result in the application executing arbitrary behaviour determined by the contents of
untrusted files.

Affected Software/OS:
MongoDB version 5.x prior to 5.0.27, 6.0.x prior to 6.0.16,
6.1.x prior to 7.0.12 and 7.1.x prior to 7.3.3.

Only environments with Windows as the underlying operating system is affected by this issue.

Solution:
Update to version 5.0.27, 6.0.16, 7.0.12, 7.3.3 or later.

CVSS Score:
6.8

CVSS Vector:
AV:L/AC:L/Au:S/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2024-7553
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.