Improper Neutralization of Argument Delimiters in a Command in XZ Utils - CVE-2024-47611

 

Improper Neutralization of Argument Delimiters in a Command in XZ Utils - CVE-2024-47611

Published: April 3, 2025


Vulnerability identifier: #VU106971
CSH Severity: High
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47611
CWE-ID: CWE-88
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper validation of arguments passed via command line to the application. A remote attacker can pass specially crafted input to the application (e.g. using a command with Unicode characters in a filename) and execute arbitrary OS commands on the system.


Affected software

XZ Utils
APEX Cloud Platform for Microsoft Azure
Storage Resource Manager
APEX Cloud Platform for Red Hat OpenShift
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2024-47611

Install updates from vendor's website.

XZ Utils - update to 5.6.3
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
APEX Cloud Platform for Red Hat OpenShift - update to 03.04.01.00
Storage Resource Manager - update to 5.0.2.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.2.2

External References

Related Security Bulletins