Loading HuntDB...

CVE-2025-1244

UNKNOWN
Published 2025-02-12T14:27:45.707Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-1244. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
8.8
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score Metrics
Exploitability: N/A Impact: N/A

EPSS Score

v2025.03.14
0.002
probability
of exploitation in the wild

There is a 0.2% chance that this vulnerability will be exploited in the wild within the next 30 days.

Updated: 2025-06-25
Exploit Probability
Percentile: 0.429
Higher than 42.9% of all CVEs

Attack Vector Metrics

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED

Impact Metrics

Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Description

A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.

Available Exploits

No exploits available for this CVE.

Related News

DSA-5871-1 emacs - security update

Two security vulnerabilities were discovered in Emacs: CVE-2024-53920 Elisp byte-compilation ('elisp-flymake-byte-compile') in the Flymake mode is now disabled for untrusted files. CVE-2025-1244 An incomplete escaping of shell meta characters in the ma…

Debian.org 2025-02-27 00:00
Emacs 30.1 released

The Emacs extensible text editor (among other things) has made a security release to address two vulnerabilities. Emacs 30.1 has fixes for CVE-2025-1244, which is a shell-command-injection flaw in the man.el man page browser and for CVE-2024-53920, which is a…

Lwn.net 2025-02-24 15:18

Affected Products

Unknown Vendor

Unknown Product

Affected Versions:

0

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

Social Media Intelligence

Real-time discussions and threat intelligence from social platforms

2 posts
Reddit 3 weeks, 2 days ago
geospeck

Emacs Ninja - CVE-2025-1244: From Emacs URL Handler to RCE

Reddit 1 month, 3 weeks ago
wasamasa

[Survey] CVE-2025-1244: Are you on Emacs 30.1 or have security patches installed? https://strawpoll.com/e7ZJa31KPg3 Hello everyone. It's been 3 months since the release of Emacs 30.1 which fixed two code execution vulnerabilities with a CVE assigned to them. One of them is CVE-2025-1244, which I want to do a blog post …

10
5
20.0

References

Published: 2025-02-12T14:27:45.707Z
Last Modified: 2025-05-22T11:22:43.603Z
Copied to clipboard!