EXPOSURES › CVE-2024-39717
CVE-2024-39717
HIGH ⌖ ON CISA KEV · EXPLOITEDVersa Director allows unauthenticated upload of malicious PNG files via the 'Change Favicon' feature, enabling remote code execution for administrators.
The Versa Director GUI permits administrators to upload arbitrary files through the 'Change Favicon' feature, bypassing file type restrictions to execute malicious code. This vulnerability is actively exploited in the wild and poses a significant risk to DIB organizations relying on Versa Director for FedRAMP compliance, as it enables remote code execution without requiring a zero-day patch.
Shame score — The vulnerability allows remote code execution through a seemingly benign UI feature, and the vendor failed to patch it before it was actively exploited in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The Versa Director GUI contains an unrestricted upload of file with dangerous type vulnerability that allows administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges to customize the user interface. The “Change Favicon” (Favorite Icon) enables the upload of a .png file, which can be exploited to upload a malicious file with a .png extension disguised as an image.