CVE-2024-12836

CVSS 3.0 Score 7.8 of 10 (high)

Details

Published Dec 30, 2024
CWE ID 843

Summary

CVE-2024-12836 is a type confusion remote code execution vulnerability affecting Delta Electronics DRASimuCAD. This issue arises from insufficient validation of user-supplied STP file data, leading to a type confusion condition. Exploitation requires user interaction, such as visiting a malicious webpage or opening a maliciously crafted file. An attacker can then execute arbitrary code in the context of the affected DRASimuCAD installation. This vulnerability, originally identified as ZDI-CAN-22450, poses a significant risk to organizations using Delta Electronics DRASimuCAD software.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share