Microsoft Security Response Center guidance
Vendor revision: Aug 12, 2026Vendor remediation details
CBL-Mariner Releases
Vendor-listed releases
- 17.0.7-4
- 3.6.2-8
- 3.7.0-3
- 19.0.4-4
Vulnerability intelligence
CVE-2024-45339 and is rated High severity with a CVSS score of 7.1. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases
Vendor-listed releases
When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.
Source: NVD