logo

CVE-2024-3094

ID: 4b09b28c-cf9b-57c7-b669-058d4846c4b7

STIX ID: report--4b09b28c-cf9b-57c7-b669-058d4846c4b7

Feed Name: Arctic Wolf Blog

Threat Score
85/100

Date Published: 2024-04-09

Date Updated: 2026-04-27

...
...

On 2024-03-29 a malicious backdoor was disclosed in XZ Utils (liblzma and related tools) affecting versions 5.6.0 and 5.6.1; the backdoor can be leveraged to bypass sshd authentication and enable remote code execution. The issue was assigned CVE-2024-3094 with a CVSS score of 10.0, a public proof-of-concept exploit exists, and multiple Linux distribution vendors have issued guidance to patch, downgrade to xz 5.4, or update affected images and snapshots.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.