CVE-2024-28285: Critical severity Cryptopp Crypto++ vulnerability
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28285?
CVE-2024-28285 has been classified as a high-severity vulnerability due to the potential for information disclosure and privilege escalation.
How do I fix CVE-2024-28285?
To fix CVE-2024-28285, you should upgrade to a patched version of Crypto++ that addresses this vulnerability.
What does CVE-2024-28285 allow an attacker to do?
CVE-2024-28285 allows an attacker co-residing on the same system as a victim process to disclose sensitive information and potentially escalate their privileges.
Which version of Crypto++ is affected by CVE-2024-28285?
CVE-2024-28285 affects Crypto++ version 8.9.
What component is vulnerable in CVE-2024-28285?
The vulnerable component in CVE-2024-28285 is the SymmetricDecrypt function located in cryptopp/elgamal.h.