CVE-2024-12044

CVSS 3.0 Score 9.8 of 10 (critical)

Details

Published Mar 20, 2025
CWE ID 502

Summary

CVE-2024-12044 is a remote code execution vulnerability affecting open-mmlab/mmdetection version v3.3.0. The issue arises from the use of `pickle.loads()` in the `all_reduce_dict()` distributed training API without proper sanitization. An attacker can exploit this vulnerability by broadcasting a malicious payload to the distributed training network, resulting in arbitrary code execution. This poses a significant risk to systems utilizing this version of the software for distributed machine learning tasks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share