V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2024-3094
ANC
CriticalConfirmedExploit available

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the li…

CVSS
10.0
Critical
EPSS
0.86
p99
Published
2024-01-01
Updated
2024-01-01
Description

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

Tags · CWE
Pre-auth
CWE-506
CAPEC-442
CAPEC-448
CAPEC-636
Affected products
Xz
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.860 · p99
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-636 · CWE-506
└ via CAPEC-636 · CWE-506
└ via CAPEC-636 · CWE-506
└ via CAPEC-448 · CWE-506
└ via CAPEC-442 · CWE-506
└ via CAPEC-636 · CWE-506
└ via CAPEC-636 · CWE-506
Known exploits — Сканер-ВС
CVE-2024-3094
github-poc · https://github.com/vesjolyjd/Kaspersky_CVE-2024-3094
Enterprise
Affected products
ProductVendorStatus
Tracked
xz-utilsTracked
xz-utilsTracked
xz-utilsTracked
xz-utilsTracked
xz-utilsTracked
xz-utilsTracked
xz-utilsTracked
xz-utilsTracked
xz*Tracked
Source databases
ANC
DEB
CVE
UBU
Related vulnerabilities