Tencent RapidJSON is vulnerable to privilege escalation due to an integer underflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer underflow vulnerability (when the file is parsed), leading to elevation of privilege.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade rapidjson | Aug 8, 2025 | Jul 9, 2024 |
| Amazon_linux_2023 | — | Upgrade rapidjson-docUpgrade rapidjson-devel | Feb 17, 2025 | Jul 9, 2024 |
| Debian | — | Upgrade rapidjson | May 15, 2025 | Jul 9, 2024 |
| Msft | — | 2024-07 Cumulative Update for Microsoft Windows 10, version 22H2 (KB5040427)2024-07 Cumulative Update for Microsoft Windows Server 2022, version 21H2 (KB5040437)2024-07 Cumulative Update for Microsoft Windows 11, version 23H2 (KB5040442)2024-07 Cumulative Update for Microsoft Windows 11, version 22H2 (KB5040442)2024-07 Cumulative Update for Microsoft Windows 11, version 21H2 (KB5040431)2024-07 Cumulative Update for Microsoft Windows 10, version 21H2 (KB5040427)2024-07 Cumulative Update for Microsoft Windows Server 2022, version 22H2 (KB5040437)2024-07 Cumulative Update for Microsoft Windows Server 2022, version 23H2 (KB5040438)2024-07 Cumulative Update for Microsoft Windows Server 2016, version 1607 (KB5040434)2024-07 Cumulative Update for Microsoft Windows 10, version 1607 (KB5040434)2024-07 Cumulative Update for Microsoft Windows Server 2019, version 1809 (KB5040430)2024-07 Cumulative Update for Microsoft Windows 10, version 1809 (KB5040430) | Jul 9, 2024 | Jul 9, 2024 |
| Ubuntu | — | Upgrade rapidjson-devUpgrade rapidjson-dev (Ubuntu Pro) | Nov 26, 2024 | Jul 9, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub