CVE-2024-24122

CVSS 3.1 Score 3.3 of 10 (low)

Details

Published Oct 2, 2024
Updated: Nov 21, 2024
CWE ID 22

Summary

CVE-2024-24122 is a remote code execution vulnerability affecting Wanxing Technology's Yitu project management system. An attacker can exploit this flaw by deceiving the system into treating an exp.adpx file as a zip compressed file. By constructing a maliciously named file, the attacker can trick the system into decompressing the project file into the system startup folder, leading to a system restart and the automatic execution of their attack script. This vulnerability poses a significant risk to the targeted system, allowing unauthorized code execution.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share