CVE-2024-35423

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 8, 2024
Updated: Nov 12, 2024
CWE ID 125

Summary

CVE-2024-35423 is a newly disclosed vulnerability affecting the vmir e8117 tool. The issue lies in the wasm_parse_section_functions function located at /src/vmir_wasm_parser.c. This function contains a heap buffer overflow, allowing attackers to potentially inject and execute malicious code during the WebAssembly module parsing process. Successful exploitation could lead to arbitrary code execution and potential compromise of the system running vmir e8117. It is recommended that users upgrade to the latest version of vmir to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share