CVE-2024-45490
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-45490 is a critical vulnerability affecting libexpat versions prior to 2.6.3, where the function xmlparse.c fails to reject negative lengths in XML_ParseBuffer. This flaw can lead to significant impacts on confidentiality, integrity, and availability due to its low attack complexity and lack of required privileges, as it can be exploited over a network without user interaction. Affected products include various implementations of libexpat, such as hAicIB, cJsLr9, and mLpYU8 among others. To remediate this vulnerability, organizations should upgrade to libexpat version 2.6.3 or later as indicated in the related patch on GitHub. The potential danger posed by this vulnerability is classified with a CVSS base score of 9.8, indicating a high risk for exploitation that could compromise organizational security.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.