CVE-2024-36814

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Oct 10, 2024
CWE ID 22

Summary

CVE-2024-36814 is a recently disclosed vulnerability in Adguard Home, affecting versions prior to 0.107.52. This issue grants authenticated attackers the ability to read arbitrary files as the root user, by uploading specially crafted files into readable directories. The vulnerability poses a significant risk, as it allows attackers to potentially access sensitive information or make unauthorized changes to critical system files. Successful exploitation of this flaw can lead to serious security consequences, including system compromise. It is strongly recommended that users upgrade to the latest version of Adguard Home to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share