CVE-2024-12747

CVSS 3.1 Score 5.6 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 362

Summary

CVE-2024-12747 is a newly disclosed vulnerability affecting the rsync utility. The issue stems from a race condition during rsync's handling of symbolic links. By default, rsync skips symbolic links. However, an attacker can exploit this vulnerability by replacing a regular file with a symbolic link at a specific moment, allowing the attacker to bypass the default behavior and traverse the symbolic link. Depending on the privileges of the rsync process, this vulnerability may result in sensitive information disclosure, potentially leading to privilege escalation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share