CVE-2024-12549

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 11, 2025
Updated: Feb 19, 2025
CWE ID 125

Summary

CVE-2024-12549 is a remote code execution vulnerability affecting Tungsten Automation Power PDF. This issue arises due to insufficient validation of user-supplied data during JP2 file parsing, resulting in an out-of-bounds read. An attacker can exploit this vulnerability by persuading the target to visit a malicious webpage or open a specially crafted file. Successful exploitation grants the attacker the ability to execute arbitrary code within the affected installation's context. (ZDI-CAN-25565) In simpler terms, CVE-2024-12549 refers to a critical flaw in Tungsten Automation Power PDF. This vulnerability enables remote attackers to execute code on affected systems by taking advantage of inadequate user data validation during JP2 file processing. The exploitation requires the target to open a maliciously crafted file or visit a malicious website.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share