CVE-2024-27322 is a critical deserialization vulnerability in the R statistical programming language, affecting versions 1.4.0 through 4.3.x. This flaw allows attackers to execute arbitrary code on a user's system by crafting malicious RDS files or R packages that are subsequently interacted with. The vulnerability carries a high CVSS score of 8.8, indicating a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. User interaction is required for exploitation. While there is no evidence of active exploitation in the wild, and no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, the vulnerability has garnered significant community attention and media coverage, suggesting a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| The R Project | R | >= 1.4.0, < 4.4.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.