CVE-2024-12703

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 17, 2025
CWE ID 502

Summary

CVE-2024-12703 is a newly identified vulnerability labeled as a deserialization of untrusted data issue (CWE-502). This weakness can put workstations at risk, allowing an attacker to potentially gain unauthorized access with loss of confidentiality, integrity, and even execute remote code. The vulnerability is triggered when a non-admin user opens a malicious project file.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share