Threat Advisory

Critical Vulnerability in R Programming Allows Supply Chain Attacks

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A critical security vulnerability, CVE-2024-27322, has been identified in the R programming language, allowing threat actors to execute arbitrary code through specially crafted RDS or rdx files. Exploiting the flaw involves leveraging promise objects and lazy evaluation in R, potentially leading to supply chain attacks via malicious R packages. Attackers can create malicious files in RDS format containing code instructions, which execute when the file is accessed, posing a significant risk to users who load compromised packages or open manipulated files. It potential for social engineering tactics to distribute these files and execute arbitrary code on victims’ devices. Projects using readRDS on untrusted files are also susceptible to exploitation, necessitating immediate attention and mitigation efforts to prevent widespread compromise.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A critical security vulnerability, CVE-2024-27322, has been identified in the R programming language, allowing threat actors to execute arbitrary code through specially crafted RDS or rdx files. Exploiting the flaw involves leveraging promise objects and lazy evaluation in R, potentially leading to supply chain attacks via malicious R packages. Attackers can create malicious files in RDS format containing code instructions, which execute when the file is accessed, posing a significant risk to users who load compromised packages or open manipulated files. It potential for social engineering tactics to distribute these files and execute arbitrary code on victims’ devices. Projects using readRDS on untrusted files are also susceptible to exploitation, necessitating immediate attention and mitigation efforts to prevent widespread compromise.[emaillocker id="1283"]

RECOMMENDATION:

  • We strongly recommend you update R Programming Language to version 4.4.0.

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/04/new-r-programming-vulnerability-exposes.html

[/emaillocker]
crossmenu