CVE-2024-6062(gpac / gpac)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swf_svg_add_iso_sample of the file src/filters/load_text.c of the component MP4Box. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as 31e499d310a48bd17c8b055a0bfe0fe35887a7cd. It is recommended to apply a patch to fix this issue. VDB-268790 is the identifier assigned to this vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gpac

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
gpac

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-10: 110-10
Referenced assets1 URL
Full discourse1 post
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows attackers chained CVE-2024-6062 and CVE-2024-6063 vulnerabilities in AhsayCBS backup platforms to deploy webshells and cryptocurrency miners. The campaign used AI-assisted PowerShell scripts that automatically suspend mining when Task Manager is detected. Runtime segmentation could have limited the blast radius from compromised backup infrastructure. #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/ahsaycbs-cve-2026-105133-105134-webshells-crypto-mining

    0000034
    2.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgpacgpac2.5-dev-rev288-g11067ea92-master--

Explore more