CVE-2024-12547

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 11, 2025
Updated: Feb 19, 2025
CWE ID 787

Summary

CVE-2024-12547 is a remote code execution vulnerability affecting Tungsten Automation Power PDF. This issue arises when the software fails to properly validate user-supplied data during JPF file parsing, resulting in an out-of-bounds write. Exploitation requires user interaction, such as visiting a malicious page or opening a crafted file. An attacker can leverage this flaw to execute arbitrary code in the context of the affected installation. The vulnerability, also known as ZDI-CAN-25560, was discovered and reported to the vendors.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share