Description
perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attackers can control the 0th argument of packed executables to execute another executable, allowing them to bypass restrictions and gain unauthorized access.
Published: 2025-12-04
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Indigostar
Indigostar perl2exe
Vendors & Products Indigostar
Indigostar perl2exe

Thu, 04 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
Description perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attackers can control the 0th argument of packed executables to execute another executable, allowing them to bypass restrictions and gain unauthorized access.
Title IndigoSTAR Software - perl2exe <= V30.10C - Arbitrary Code Execution
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Indigostar Perl2exe
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-04-07T14:08:32.177Z

Reserved: 2025-12-04T16:32:25.980Z

Link: CVE-2024-58278

cve-icon Vulnrichment

Updated: 2025-12-05T16:46:18.983Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-04T21:16:07.867

Modified: 2025-12-08T18:27:15.857

Link: CVE-2024-58278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-05T10:52:25Z

Weaknesses