CVE-2024-49394
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Nov 12, 2024
Updated: Nov 14, 2024
CWE ID 347
Summary
CVE-2024-49394 is a vulnerability affecting both mutt and neomutt email clients. This issue lies in the lack of cryptographic signing for the In-Reply-To email header field. An attacker can exploit this vulnerability by reusing an unencrypted but signed email message, allowing them to impersonate the original sender. This poses a significant risk for email spoofing and phishing attacks. Users are advised to update their email clients to the latest version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.