01/09/2025
▶ CVE-2024-9129: Format String Injection in Zend Server
In this blog post, I want to share some details about a vulnerability I identified in the Zend Server product by Perfoce, versions 8.5 and prior to version 9.2. The vulnerability is a format string issue, a well-known category of flaws commonly associated with binary exploitation, and in this case, it is exploitable via web (HTTP).