CVE-2024-25431

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 8, 2024
Updated: Nov 14, 2024
CWE ID 125

Summary

CVE-2024-25431 is a privilege escalation vulnerability affecting the bytecodealliance wasm-micro-runtime before version b3f728c. A remote attacker can exploit this issue by providing a specially crafted file, which allows them to escalate privileges and gain unauthorized access to the check_was_abi_compatibility function. The vulnerability was addressed in commit 06df58f. This issue poses a serious risk to systems utilizing the affected wasm-micro-runtime version and should be addressed promptly through updates or patches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share