OneDrive
by Microsoft
CVEs (15)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-0654 | Cri | 0.59 | 9.1 | 0.03 | Jan 14, 2020 | A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to bypass the passcode or fingerprint requirements of the App.The security update addresses the vulnerability by correcting the way Microsoft OneDrive App for… | ||
| CVE-2023-24930 | Hig | 0.51 | 7.8 | 0.00 | Mar 14, 2023 | Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability | ||
| CVE-2020-1465 | Hig | 0.51 | 7.8 | 0.01 | Jul 14, 2020 | An elevation of privilege vulnerability exists in Microsoft OneDrive that allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft OneDrive Elevation of Privilege Vulnerability'. | ||
| CVE-2018-0593 | Hig | 0.51 | 7.8 | 0.05 | Jun 26, 2018 | Untrusted search path vulnerability in the installer of Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | ||
| CVE-2018-0592 | Hig | 0.51 | 7.8 | 0.05 | Jun 26, 2018 | Untrusted search path vulnerability in Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | ||
| CVE-2020-16853 | Hig | 0.46 | 7.1 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this… | ||
| CVE-2020-16852 | Hig | 0.46 | 7.1 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this… | ||
| CVE-2020-16851 | Hig | 0.46 | 7.1 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this… | ||
| CVE-2026-65680 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-60722 | Med | 0.42 | 6.5 | 0.01 | Nov 11, 2025 | Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2023-24890 | Med | 0.42 | 6.5 | 0.01 | Mar 14, 2023 | Microsoft OneDrive for iOS Security Feature Bypass Vulnerability | ||
| CVE-2022-23255 | Med | 0.38 | 5.9 | 0.01 | Feb 9, 2022 | Microsoft OneDrive for Android Security Feature Bypass Vulnerability | ||
| CVE-2023-24923 | Med | 0.36 | 5.5 | 0.01 | Mar 14, 2023 | Microsoft OneDrive for Android Information Disclosure Vulnerability | ||
| CVE-2023-24882 | Med | 0.36 | 5.5 | 0.01 | Mar 14, 2023 | Microsoft OneDrive for Android Information Disclosure Vulnerability | ||
| CVE-2020-0935 | Med | 0.36 | 5.5 | 0.01 | Apr 15, 2020 | An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows Elevation of Privilege Vulnerability'. |
- risk 0.59cvss 9.1epss 0.03
A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to bypass the passcode or fingerprint requirements of the App.The security update addresses the vulnerability by correcting the way Microsoft OneDrive App for…
- risk 0.51cvss 7.8epss 0.00
Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists in Microsoft OneDrive that allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft OneDrive Elevation of Privilege Vulnerability'.
- risk 0.51cvss 7.8epss 0.05
Untrusted search path vulnerability in the installer of Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- risk 0.51cvss 7.8epss 0.05
Untrusted search path vulnerability in Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this…
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this…
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this…
- risk 0.44cvss 6.7epss 0.00
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
- risk 0.42cvss 6.5epss 0.01
Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over a network.
- risk 0.42cvss 6.5epss 0.01
Microsoft OneDrive for iOS Security Feature Bypass Vulnerability
- risk 0.38cvss 5.9epss 0.01
Microsoft OneDrive for Android Security Feature Bypass Vulnerability
- risk 0.36cvss 5.5epss 0.01
Microsoft OneDrive for Android Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Microsoft OneDrive for Android Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows Elevation of Privilege Vulnerability'.