CVE-2024-28109
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Mar 28, 2024
CWE ID 91
Summary
CVE-2024-28109 is a remote code execution (RCE) vulnerability affecting the veraPDF-library, a PDF/A validation tool. The issue arises when processing custom schematron files during policy checks, which in turn triggers an XSL transformation. Malicious actors could exploit this flaw to execute arbitrary code on vulnerable systems. Users are advised to upgrade to version 1.24.2 to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share