nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-58278 CVE-2024-58278
HIGH
IndigoSTAR Software - perl2exe <= V30.10C - Arbitrary Code Execution
Record summary
CVE-2024-58278 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attackers can control the 0th argument of packed executables to execute another executable, allowing them to bypass restrictions and gain unauthorized access.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 5, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through V30.10C | affected |
Proofs of concept
1Catalogued exploits
ExploitDBExecutables Created with perl2exe < V30.10C - Arbitrary Code ExecutionExploitDB exploitby decrazyoNot analyzed1 file
References
5ExploitDB-51825exploit
https://www.exploit-db.com/exploits/51825 IndigoSTAR Software Homepageproduct
https://www.indigostar.com/ IndigoSTAR Software Download Pageproductpermissions required
https://www.indigostar.com/download/p2x-30.10-Linux-x64-5.30.1.tar.gz vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/indigostar-software-perl2exe-v3010c-arbitrary-code-execution