CVE-2024-27102
CVSS 3.1 Score 9.9 of 10 (high)
Details
Summary
CVE-2024-27102 is a newly disclosed vulnerability affecting the Wings server control plane used by Pterodactyl Panel. Anyone operating versions prior to 1.11.9 of Wings is potentially impacted. The vulnerability enables an attacker to access files and directories on the host system, though the extent of the impact is currently unknown. exploitation requires an attacker to have control of an allocated "server" within Wings. The exploit details are currently under embargo, with disclosure scheduled for March 27, 2024, 18:00 UTC. The vulnerability necessitated a complete rewrite of the server filesystem, resulting in a large patch. Users are strongly encouraged to update immediately to mitigate the risk. No known workarounds exist for this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.