CVE-2024-56334

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Dec 20, 2024
Updated: Dec 24, 2024
CWE ID 94

Summary

CVE-2024-56334 is a newly disclosed vulnerability affecting the systeminformation library for node.js. In vulnerable versions, the SSID parameter passed to cmd.exe in the getWindowsIEEE8021x function is not properly sanitized, allowing malicious content in the SSID to be executed as OS commands. This issue could potentially enable remote code execution or local privilege escalation, depending on how the package is used. The vulnerability has been addressed in version 5.23.7, and all users are urged to upgrade as soon as possible. No known workarounds are currently available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share