Researchers at HiddenLayer found a critical vulnerability in R, a popular programming language for statistical computing and machine learning, that allows attackers to execute arbitrary code. This vulnerability, identified as CVE-2024-27322, is exploitable through RDS (R Data Serialization) files or R packages. R's serialization and deserialization process, used in creating and loading RDS files and packages, is the weak point. An attacker can create a file that, when deserialized, executes arbitrary code. The R team has quickly patched this vulnerability in R v4.4.0.
https://hiddenlayer.com/research/r-bitrary-code-execution/
#cybersecurity #R #vulnerability #patch #update #HiddenLayer