Lucene search

K
wizblogWiz BlogWIZBLOG:BABAEABBA55C1AF14806159B284EF03E
HistoryMar 29, 2024 - 10:02 p.m.

Backdoor in XZ Utils allows RCE: everything you need to know

2024-03-2922:02:58
Wiz Blog
www.wiz.io
88
xz utils
rce
cve-2024-3094
supply chain compromise
patch urgency

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

7

Confidence

Low

EPSS

0.144

Percentile

95.8%

Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgently.

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

7

Confidence

Low

EPSS

0.144

Percentile

95.8%