CVE-2024-29510 is a memory corruption vulnerability in Artifex Ghostscript versions prior to 10.03.1, allowing for a SAFER sandbox bypass through format string injection with a uniprint device. This vulnerability carries a CVSS score of 6.3 (Medium) due to its local attack vector and low attack complexity, potentially leading to high confidentiality impact. Although not in the KEV catalog, exploit intelligence indicates active exploitation, with a Metasploit module available and significant community discussion and media coverage, including reports of it being exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.03.1CPE matchmatch criteria | cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.