CVE-2022-49043
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Jan 26, 2025
CWE ID 416
Summary
CVE-2022-49043 is a vulnerability affecting libxml2 versions prior to 2.11.0. The issue lies in the xmlXIncludeAddNode function found in xinclude.c. A use-after-free condition exists in this function, which can lead to memory corruption and potential code execution if an attacker can manipulate an XML document to trigger the vulnerability. Successful exploitation could result in serious security implications, including data theft or system compromise. Users are advised to upgrade to the latest version of libxml2 to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.