CVE-2024-56334
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-56334 is a newly disclosed vulnerability affecting the systeminformation library for node.js. In vulnerable versions, the SSID parameter passed to cmd.exe in the getWindowsIEEE8021x function is not properly sanitized, allowing malicious content in the SSID to be executed as OS commands. This issue could potentially enable remote code execution or local privilege escalation, depending on how the package is used. The vulnerability has been addressed in version 5.23.7, and all users are urged to upgrade as soon as possible. No known workarounds are currently available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.