CVE-2024-39755

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 3, 2024
Updated: Dec 18, 2024
CWE ID 282

Summary

CVE-2024-39755 is a newly disclosed privilege escalation vulnerability that affects the node update functionality in Veertu Anka Build 1.42.0. Maliciously crafted PKG files can be used to execute privileged operations, allowing unauthenticated attackers to exploit this vulnerability by making an HTTP request. This issue poses a significant risk to systems utilizing Veertu Anka Build 1.42.0 and demands immediate attention for patching and mitigation efforts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share