CVE-2024-12835

CVSS 3.0 Score 7.8 of 10 (high)

Details

Published Dec 30, 2024
CWE ID 787

Summary

CVE-2024-12835 is a remote code execution vulnerability affecting Delta Electronics DRASimuCAD. This issue stems from insufficient validation of user-supplied data during ICS file parsing, resulting in an out-of-bounds write. For exploitation, an attacker needs the target to visit a malicious page or open a malicious file. This vulnerability, discovered as ZDI-CAN-22415, enables an attacker to execute arbitrary code in the context of the current process.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share