Exploit for #VU87917 Embedded malicious code (backdoor) in XZ Utils


Published: 2024-04-03 | Updated: 2024-04-19

Vulnerability identifier: #VU87917

Vulnerability risk: Critical

CVSSv3.1: 9.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:U/RC:C]

CVE-ID: CVE-2024-3094

CWE-ID: CWE-506

Exploitation vector: Network

Exploits in database: 2

  • April 19, 2024
  • April 3, 2024

Impact: Code execution

Vulnerable software:
XZ Utils
Universal components / Libraries / Libraries used by multiple products

Vendor: tukaani.org