R language flaw allows code execution via RDS/RDX files
ID: 8c9ec6e8-97eb-50bc-a725-7b3c53802e86
STIX ID: report--8c9ec6e8-97eb-50bc-a725-7b3c53802e86
Feed Name: Bleeping Computer
Threat Score
HiddenLayer disclosed CVE-2024-27322, a high-severity R deserialization vulnerability (CVSS 8.8) that allows arbitrary code execution via crafted RDS/RDX files by embedding promise objects evaluated during readRDS; organizations should upgrade to R Core 4.4.0 (which restricts promises in the serialization stream) and sandbox or otherwise isolate untrusted R data and packages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
