CVE-2024-25431: High severity bytecode alliance webassembly micro runtime vulnerability
Published Nov 8, 2024
·Updated
An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the checkwasabicompatibility function.
Affected Software
1 affected component
bytecodealliance Webassembly Micro Runtime<1.3.2
Remediation
Event History
Nov 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25431?
CVE-2024-25431 has a severity rating that indicates a potential for privilege escalation if exploited.
2
How do I fix CVE-2024-25431?
To fix CVE-2024-25431, update the WebAssembly Micro Runtime to version 1.3.2 or later.
3
Who is affected by CVE-2024-25431?
CVE-2024-25431 affects users of bytecodealliance's WebAssembly Micro Runtime prior to version 1.3.2.
4
What functionality is impacted by CVE-2024-25431?
The vulnerability in CVE-2024-25431 impacts the check_was_abi_compatibility function, allowing for privilege escalation.
5
When was CVE-2024-25431 disclosed?
CVE-2024-25431 was disclosed prior to the fix being implemented in commit 06df58f.