CVE-2024-39755
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Oct 3, 2024
Updated: Dec 18, 2024
CWE ID 282
Summary
CVE-2024-39755 is a newly disclosed privilege escalation vulnerability that affects the node update functionality in Veertu Anka Build 1.42.0. Maliciously crafted PKG files can be used to execute privileged operations, allowing unauthenticated attackers to exploit this vulnerability by making an HTTP request. This issue poses a significant risk to systems utilizing Veertu Anka Build 1.42.0 and demands immediate attention for patching and mitigation efforts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.