CVE-2024-28285: Cryptopp Crypto\+\+

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.

Affected products

Published 2024-05-14. Last modified 2026-06-17.