CVE-2024-27102

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Mar 13, 2024
Updated: Mar 14, 2024
CWE ID 22
CWE ID 362
CWE ID 363

Summary

CVE-2024-27102 is a newly disclosed vulnerability affecting the Wings server control plane used by Pterodactyl Panel. Anyone operating versions prior to 1.11.9 of Wings is potentially impacted. The vulnerability enables an attacker to access files and directories on the host system, though the extent of the impact is currently unknown. exploitation requires an attacker to have control of an allocated "server" within Wings. The exploit details are currently under embargo, with disclosure scheduled for March 27, 2024, 18:00 UTC. The vulnerability necessitated a complete rewrite of the server filesystem, resulting in a large patch. Users are strongly encouraged to update immediately to mitigate the risk. No known workarounds exist for this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share