Vulnerabilities
Vulnerable Software
Microsoft:  >> Onedrive  Security Vulnerabilities
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
CVSS Score
6.7
EPSS Score
0.003
Published
2026-08-11
Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over a network.
CVSS Score
6.5
EPSS Score
0.008
Published
2025-11-11
Microsoft OneDrive for Android Information Disclosure Vulnerability
CVSS Score
5.5
EPSS Score
0.008
Published
2023-03-14
Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.005
Published
2023-03-14
Microsoft OneDrive for Android Information Disclosure Vulnerability
CVSS Score
5.5
EPSS Score
0.007
Published
2023-03-14
Microsoft OneDrive for iOS Security Feature Bypass Vulnerability
CVSS Score
6.5
EPSS Score
0.012
Published
2023-03-14
Microsoft OneDrive for Android Security Feature Bypass Vulnerability
CVSS Score
5.9
EPSS Score
0.006
Published
2022-02-09
<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status.</p> <p>To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and delete a targeted file with an elevated status.</p> <p>The update addresses this vulnerability by correcting where the OneDrive updater performs file writes while running with elevation.</p>
CVSS Score
7.1
EPSS Score
0.01
Published
2020-09-11
<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status.</p> <p>To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and delete a targeted file with an elevated status.</p> <p>The update addresses this vulnerability by correcting where the OneDrive updater performs file writes while running with elevation.</p>
CVSS Score
7.1
EPSS Score
0.009
Published
2020-09-11
<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status.</p> <p>To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and delete a targeted file with an elevated status.</p> <p>The update addresses this vulnerability by correcting where the OneDrive updater performs file writes while running with elevation.</p>
CVSS Score
7.1
EPSS Score
0.01
Published
2020-09-11


Contact Us

Shodan ® - All rights reserved