Hex-Rays IDA Pro
cpe:2.3:a:hex-rays:ida_pro:*:*:*:*:*:*:*
- >= 9.2, < 9.3sp2
A vulnerability exists in Hex-Rays IDA Pro versions 9.2 and 9.3 prior to 9.3sp2, where the application does not properly restrict Clang dependency-file generation. This oversight allows attackers to inject code into a .i64 file, which can then be placed into a plugin directory used by IDA Pro.
Exploitation of this vulnerability could lead to unauthorized code execution within the IDA Pro environment, potentially allowing for the creation of malicious plugins that could be executed by the user.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.