EXPOSURES › CVE-2024-7694
CVE-2024-7694
HIGH ⌖ ON CISA KEV · EXPLOITEDTeamT5's ThreatSonar suffered an unrestricted file upload flaw, allowing remote code execution for attackers with admin access.
TeamT5's ThreatSonar Anti-Ransomware allowed unrestricted file uploads without proper validation, enabling remote attackers with admin privileges to upload malicious files and execute arbitrary system commands. This could lead to significant system compromise.
Shame score — Critical unpatched vulnerability enabling remote code execution for high-privileged users.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system commands on the server.