CVE-2024-47556

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 7, 2024
Updated: Oct 16, 2024
CWE ID 22

Summary

CVE-2024-47556 is a newly disclosed vulnerability that allows an unauthenticated attacker to achieve remote code execution (RCE) on a targeted system. This vulnerability is caused by a path traversal issue, enabling the attacker to manipulate file paths and access sensitive files or execute arbitrary code. The exploitation does not require any authentication or user interaction, making it especially dangerous for affected organizations. The exact cause and the affected software or platform have not been disclosed yet, but it is recommended that affected parties apply patches or workarounds as soon as they become available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share