Code Injection Vulnerability in Hex-Rays IDA Pro by Hex-Rays
CVE-2026-45181
6.5MEDIUM
What is CVE-2026-45181?
Hex-Rays IDA Pro versions 9.2 and 9.3 prior to 9.3sp2 are susceptible to a code injection vulnerability due to inadequate handling of Clang dependency-file generation via argument injection. By exploiting this flaw, an attacker can craft a malicious .i64 file, allowing them to inject their code into the plugin directory of the affected system if the victim inadvertently processes this file. This weakness poses a significant threat to users of IDA Pro, as it enables unauthorized code execution and potential system compromise.
Affected Version(s)
IDA 9.2 < 9.3sp2
