ZeroHour

CVE-2024-38395

CVSS 3.1
9.8 critical
EPSS
1%p73
Published
()
Modified
Description

In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."

Vendors
iterm2
Products
iterm2
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.