CVE-2024-26256
Libarchive Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
libarchive Remote Code Execution Vulnerability
Vulnerabilidad de ejecución remota de código de libarchive
Libarchive Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of libarchive. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.
The specific flaw exists within the run_filters method. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
An integer overflow vulnerability in the rar e8 filter was discovered in libarchive, a multi-format archive and compression library, which may result in the execution of arbitrary code if a specially crafted RAR archive is processed.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-02-15 CVE Reserved
- 2024-04-09 CVE Published
- 2025-01-23 CVE Updated
- 2025-04-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-122: Heap-based Buffer Overflow
CAPEC
References (9)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26256 | 2024-06-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Windows 11 Version 22H2 Search vendor "Microsoft" for product "Windows 11 Version 22H2" | >= 10.0.22621.0 < 10.0.22621.3447 Search vendor "Microsoft" for product "Windows 11 Version 22H2" and version " >= 10.0.22621.0 < 10.0.22621.3447" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 11 Version 22H3 Search vendor "Microsoft" for product "Windows 11 Version 22H3" | >= 10.0.22631.0 < 10.0.22631.3447 Search vendor "Microsoft" for product "Windows 11 Version 22H3" and version " >= 10.0.22631.0 < 10.0.22631.3447" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 11 Version 23H2 Search vendor "Microsoft" for product "Windows 11 Version 23H2" | >= 10.0.22631.0 < 10.0.22631.3447 Search vendor "Microsoft" for product "Windows 11 Version 23H2" and version " >= 10.0.22631.0 < 10.0.22631.3447" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2022, 23H2 Edition (Server Core Installation) Search vendor "Microsoft" for product "Windows Server 2022, 23H2 Edition (Server Core Installation)" | >= 10.0.25398.0 < 10.0.25398.830 Search vendor "Microsoft" for product "Windows Server 2022, 23H2 Edition (Server Core Installation)" and version " >= 10.0.25398.0 < 10.0.25398.830" | en |
Affected
|