CVE-2024-25376: Code Injection
Published Apr 11, 2024
·Updated
An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbitrary code via the msiexec.exe repair mode.
Affected Software
2 affected components
Thesycon Software Solutions GmbH & Co. KG TUSBAudio<5.68.0
Thesycon TUSBAudio<5.68.0
Event History
Apr 11, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25376?
CVE-2024-25376 is identified as a high severity vulnerability due to its potential to allow local attackers to execute arbitrary code.
2
How do I fix CVE-2024-25376?
To fix CVE-2024-25376, upgrade Thesycon TUSBAudio to version 5.68.0 or later.
3
Who is affected by CVE-2024-25376?
CVE-2024-25376 affects users of Thesycon TUSBAudio MSI-based installers prior to version 5.68.0.
4
What type of attack does CVE-2024-25376 enable?
CVE-2024-25376 enables local attackers to execute arbitrary code through the msiexec.exe repair mode.
5
Is there a workaround for CVE-2024-25376?
There are no documented workarounds for CVE-2024-25376; the recommended action is to update the software.