CVE-2024-53977
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Published Feb 11, 2025
CWE ID 427
Summary
CVE-2024-53977 is a recently discovered vulnerability affecting ModelSim versions below V2025.1 and Questa versions below V2025.1. The issue stems from a script in these applications that allows loading of a specific executable file from the current working directory. An attacker with authenticated local access can exploit this vulnerability to inject arbitrary code and escalate privileges. This is a significant risk for installations where administrators or privileged processes launch the script from a user-writable directory.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share