CVE-2024-9761

CVSS 3.1 Score 3.3 of 10 (low)

Details

Published Nov 22, 2024
Updated: Dec 5, 2024
CWE ID 125

Summary

CVE-2024-9761 is a newly disclosed vulnerability impacting Tungsten Automation Power PDF. This information disclosure issue permits remote attackers to obtain sensitive data from affected systems by exploiting a buffer read vulnerability during PDF file parsing. The root cause of this flaw lies in insufficient validation of user-supplied data, enabling an attacker to read beyond the allocated buffer boundaries. User interaction is necessary to exploit this vulnerability, as the target must either visit a malicious webpage or open a maliciously crafted PDF file. This issue, also known as ZDI-CAN-24477, could potentially be combined with other vulnerabilities to execute arbitrary code.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share