CVE-2024-7265 - CVE House
Back to Database
Status published High CVE-2024-7265

Privilege Escalation in EZD RP

Vulnerability Description

Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any user, including root user, which could lead to privilege escalation. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-7265

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Jakub Płatek (NASK-PIB)

Affected Vendor

Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy

View all reports →

Affected Software

EZD RP
Vulnerable Versions:
15, 16, 17

Timeline

Official Publish: August 7th, 2024
Last Modified: March 17th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)