CVE-2024-49777

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 120

Summary

CVE-2024-49777 is a newly disclosed vulnerability affecting the tsMuxer media player, specifically versions nightly-2024-03-14-01-51-12 and older. This issue involves a heap-based buffer overflow, which can be exploited by attackers to mount a Denial of Service (DoS) attack, steal sensitive information, or execute malicious code. The vulnerability is triggered by a specially crafted MKV video file, making it a significant threat to systems that use this media player. Successful exploitation of this vulnerability could result in serious consequences, including system crashes, data leaks, or unauthorized code execution. Users are advised to update their tsMuxer software to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share