CVE-2024-45152

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 9, 2024
Updated: Oct 18, 2024
CWE ID 787

Summary

CVE-2024-45152 is a newly disclosed vulnerability that affects Substance3D's Stager software versions 3.0.3 and older. This issue involves an out-of-bounds write vulnerability, which, when exploited, could lead to arbitrary code execution. The exploitation of this flaw requires user interaction, meaning a victim must open a maliciously crafted file to be vulnerable. Successful exploitation could potentially grant an attacker the same privileges as the current user. This vulnerability poses a significant risk to users and highlights the importance of keeping software up-to-date to protect against known security vulnerabilities.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share