CVE-2024-24122: Wondershare Edraw

Low severity, CVSS 3.3. EPSS: 0.7% chance of exploitation in the next 30 days.

A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project file into the system startup folder, restart the system, and automatically execute the constructed attack script.

Affected products

Published 2024-10-02. Last modified 2026-06-17.