CVE-2024-9761
CVSS 3.1 Score 3.3 of 10 (low)
Details
Summary
CVE-2024-9761 is a newly disclosed vulnerability impacting Tungsten Automation Power PDF. This information disclosure issue permits remote attackers to obtain sensitive data from affected systems by exploiting a buffer read vulnerability during PDF file parsing. The root cause of this flaw lies in insufficient validation of user-supplied data, enabling an attacker to read beyond the allocated buffer boundaries. User interaction is necessary to exploit this vulnerability, as the target must either visit a malicious webpage or open a maliciously crafted PDF file. This issue, also known as ZDI-CAN-24477, could potentially be combined with other vulnerabilities to execute arbitrary code.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.