Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.
CVE ID: CVE-2024-49071
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.5
Vendor: Microsoft
Product: Microsoft Defender for Endpoint for Windows
EPSS Score: 0.06% (probability of being exploited)
EPSS Percentile: 29.87% (scored less or equal to compared to others)
EPSS Date: 2025-02-06 (when was this score calculated)