Tencent · Rapidjson · CVE-2024-38517
**Name of the Vulnerable Software and Affected Versions**
Tencent RapidJSON (affected versions not specified)
**Description**
The issue is related to an integer underflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. This can be exploited by an attacker sending a crafted file to the victim, which when opened, triggers the integer underflow vulnerability, leading to elevation of privilege. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.