CVE-2024-46632

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Sep 30, 2024
CWE ID 122

Summary

CVE-2024-46632 is a newly disclosed cybersecurity vulnerability affecting Assimp v5.4.3. Hackers can exploit this issue by supplying malicious data to the MD5Importer::LoadMD3MeshFile function, leading to a buffer overflow condition. Successful exploitation may result in arbitrary code execution or denial-of-service attacks. Developers are advised to update to the latest version of Assimp or apply the available patch to mitigate this risk. Users who cannot upgrade immediately should take extra precautions to prevent exposure to potential attack vectors.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share