CVE-2024-57509

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 29, 2025
Updated: Jan 31, 2025
CWE ID 120

Summary

CVE-2024-57509 is a newly discovered buffer overflow vulnerability affecting the Bento4 mp42avc video component, version 3bdc891602d19789b8e8626e4a3e613a937b4d35. This issue permits a local attacker to exploit the AP4_File::ParseStream function and related ones, leading to arbitrary code execution. The vulnerability can be potentially exploited to gain unauthorized access or control over an affected system. The impact of this vulnerability is significant as it could lead to serious security risks. Users are advised to update their Bento4 mp42avc component to a patched version as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share