Impact
A race condition in MongoDB Server’s document value layer allows concurrent server threads to access the same internal memory without proper synchronization, which can lead to memory corruption. An authenticated user with ordinary read-write rights can trigger the issue through the standard client protocol and corrupt process memory with data influenced by the attacker. This may compromise server process.
Affected Systems
MongoDB Server is affected. No specific version details are listed, so all MongoDB Server deployments could be vulnerable unless they have applied the fix for SERVER-134063.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.7, indicating a high severity. The EPSS score is < 1%, indicating a very low exploitation probabilityISA’s KEV catalog. Based on the description, the likely attack vector involves an authenticated user performing database operations that create concurrent access. While a successful exploit could result in denial of that might lead to further compromise, the exact exploitation path requires sufficient concurrency and is unlikely to be automated without the necessary privileges.
OpenCVE Enrichment