CVE-2024-52065 is a classic buffer overflow vulnerability affecting RTI Connext Professional versions 7.0.0 through 7.3.0.1, 6.1.1.2 through 6.1.2.20, and 5.3.1.40. This high-severity vulnerability (CVSS 7.1) allows an attacker to achieve high integrity and availability impact by exploiting the Persistence Service on non-Windows systems through crafted environment variables, requiring user interaction. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for significant disruption warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.1.1.2, < 6.1.2.21CPE matchmatch criteria | cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.3.0.2CPE matchmatch criteria | cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:* | ||
5.3.1.40CPE matchmatch criteria | cpe:2.3:a:rti:connext_professional:5.3.1.40:*:*:*:*:*:*:* | ||
>= 5.3.1.40, < 5.3.1.41CPE match | cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.