← back
CVE-2024-32944

CVE-2024-32944

CVSS 3.3 LOWEPSS 0.2%CWE-22
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.3EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
28 May 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Path traversal vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product installs a crafted UTAU voicebank installer (.uar file, .zip file) to UTAU, an arbitrary file may be placed.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected products
ameya/ayame · UTAU