CVE-2024-12551

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 11, 2025
Updated: Feb 18, 2025
CWE ID 125

Summary

CVE-2024-12551 is a remote code execution vulnerability affecting Tungsten Automation Power PDF. This issue arises due to insufficient validation of user-supplied data during the processing of JP2 files. An attacker can exploit this out-of-bounds read vulnerability by crafting a malicious JP2 file that causes the software to read past the intended memory boundary. Successful exploitation allows the attacker to execute arbitrary code in the context of the affected installation. User interaction is required for exploitation, as the target must visit a malicious webpage or open the malicious file.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share