CVE-2024-32632

CVSS 3.1 Score 6.6 of 10 (medium)

Details

Published Apr 16, 2024
CWE ID 686

Summary

CVE-2024-32632 is a newly disclosed vulnerability that affects the handling of a value in ATCMD, a command-line utility. The issue arises when printf misinterprets the value, resulting in incorrect output. In certain scenarios, this can lead to out-of-bounds memory access, potentially causing security vulnerabilities or application crashes. Exploitation requires a specially crafted input and may result in unintended program behavior. Organizations are advised to apply relevant patches as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share