CVE-2024-13046

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Dec 30, 2024
Updated: Jan 3, 2025
CWE ID 787

Summary

CVE-2024-13046 is a remote code execution vulnerability affecting Ashlar-Vellum Cobalt software. The issue arises due to insufficient validation of user-supplied data during CO file parsing, leading to an out-of-bounds write. This vulnerability necessitates user interaction, as the target must visit a malicious webpage or open a malicious file for exploitation. An attacker can capitalize on this flaw to execute arbitrary code within the affected system. The vulnerability, originally identified as ZDI-CAN-24867, underscores the importance of robust data validation practices in software development.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share