Malicious code embedded in the popular XZ Utils data compression library (CVE-2024-3094)

Vulnerability Assessment

  • ID: CVE-2024-3094
  • Score: 10 (out of 10)
  • Severity: Critical
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction Required: None
  • Attack Scope in case of successful exploit: Entire System
  • Impact on Data Privacy: High
  • Impact on Data Integrity: High
  • Impact on Availability: High

 

Technical Description:

It is under review