CVE-2024-27934
CVSS 3.1 Score 8.4 of 10 (high)
Details
Summary
CVE-2024-27934 is a critical vulnerability affecting Deno, a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.36.2 and earlier, up to 1.40.2, are impacted. The flaw arises due to the use of inherently unsafe `*const c_void` and `ExternalPointer`, leading to use-after-free access of underlying structures. An attacker can exploit this vulnerability by controlling the code executed within a Deno runtime to execute arbitrary code on the host machine, regardless of permissions. Both `*const c_void` and `ExternalPointer` implementations are susceptible to this issue. Version 1.40.3 has been released to address this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.