Copy of R Programming Language Vulnerable to Attack
Access Point Consulting
Hands-on cybersecurity for small to mid-sized companies.
Report by Matthew Fagan, Access Point Consulting
A vulnerability present in the R programming language on versions 1.4.0 through 4.4.0., categorized as CVE-2024-27322 (CVSSv3: 8.8), allows a remote attacker to send a maliciously crafted RDS-formatted file or R package to run arbitrary code on a user’s system. This vulnerability requires the user to interact with the RDS formatted file or R package. The research for this vulnerability comes from HiddenLayer. Read more