Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue affects MongoDB Server v5.0 versions prior to 5.0.27, MongoDB Server v6.0 versions prior to 6.0.16, MongoDB Server v7.0 versions prior to 7.0.12, MongoDB Server v7.3 versions prior 7.3.3, MongoDB C Driver versions prior to 1.26.2 and MongoDB PHP Driver versions prior to 1.18.1. Required Configuration: Only environments with Windows as the underlying operating system is affected by this issue
Conclusion & alert: CVE-2024-7553 is rated Moderate Risk (44.9/100): CVSS High severity, with low exploitation likelihood (EPSS 0.22%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-04 | 0.09% | 0.22% | +0.13% |
| 2 | 2026-03-01 | 0.24% | 0.09% | -0.15% |
| 3 | 2026-02-04 | — | 0.24% | — |
Full EPSS history (13 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.3 | 3.1 | HIGH |
|
1.3 | 5.9 | [email protected] |
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2024-7553 medium priority: Ubuntu including 3 source packages (mongo-c-driver, mongodb, php-mongodb), 23 status rows across 9 suites (bionic, focal, jammy, noble, oracular, plucky, trusty, upstream, xenial): ignored 16, DNE 4, released 3. | https://ubuntu.com/security/CVE-2024-7553 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| mongodb | mongodb | >= 5.0.0, < 5.0.27 | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* |
| mongodb | mongodb | >= 6.0.0, < 6.0.16 | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* |
| mongodb | mongodb | >= 7.0.0, < 7.0.12 | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* |
| mongodb | mongodb | >= 7.3.0, < 7.3.3 | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* |
| mongodb | c_driver | < 1.26.2 | cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:* |
| mongodb | php_driver | < 1.18.1 | cpe:2.3:a:mongodb:php_driver:*:*:*:*:*:mongodb:*:* |
| URL | Tags |
|---|---|
| https://jira.mongodb.org/browse/CDRIVER-5650 | Vendor Advisory |
| https://jira.mongodb.org/browse/PHPC-2369 | Vendor Advisory |
| https://jira.mongodb.org/browse/SERVER-93211 | Vendor Advisory |