CVE-2024-12345

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Jan 27, 2025
CWE ID 404
CWE ID 400

Summary

CVE-2024-12345 is a newly identified vulnerability affecting the INW Krbyyyzo 25.2002 component. Specifically, an unknown functionality in the file /gbo.aspx of the Daily Huddle Site is the culprit. Maliciously crafted input to the argument s triggers excessive resource consumption, potentially allowing an attacker to launch an attack on the local host. Further investigation suggests that other endpoints could also be susceptible to this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share