CVE-2024-12044
CVSS 3.0 Score 9.8 of 10 (critical)
Details
Published Mar 20, 2025
CWE ID 502
Summary
CVE-2024-12044 is a remote code execution vulnerability affecting open-mmlab/mmdetection version v3.3.0. The issue arises from the use of `pickle.loads()` in the `all_reduce_dict()` distributed training API without proper sanitization. An attacker can exploit this vulnerability by broadcasting a malicious payload to the distributed training network, resulting in arbitrary code execution. This poses a significant risk to systems utilizing this version of the software for distributed machine learning tasks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.