CVE-2024-12550

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 11, 2025
Updated: Feb 20, 2025
CWE ID 125

Summary

CVE-2024-12550 is an out-of-bounds read information disclosure vulnerability affecting Tungsten Automation Power PDF. This issue arises from improper validation of user-supplied data during JP2 file parsing, enabling remote attackers to disclose sensitive information. User interaction is necessary for exploitation, either through visiting a malicious webpage or opening a malicious file. An attacker could potentially combine this vulnerability with others to execute arbitrary code. (ZDI-CAN-25566)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share