CVE-2024-25200
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-25200 is a newly disclosed vulnerability affecting Espruino 2v20, specifically the commit fcc9ba4. This issue involves a Stack Overflow vulnerability, which can be triggered through the jspeFactorFunctionCall found in src/jsparse.c. The Stack Overflow vulnerability occurs when the interpreter fails to allocate sufficient stack space, causing the system to crash and potentially leading to exploitation. Attackers could exploit this flaw by crafting malicious JavaScript code that triggers the stack overflow condition, resulting in a denial-of-service (DoS) or potentially more serious consequences. Users are advised to update their Espruino installations as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.