CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2024-48063: In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.

criticalCVSS 9.8CVE-2024-48063

CSIRTS triage

What
RemoteModule deserialization in PyTorch allows remote code execution by deserializing untrusted data.
Who is affected
PyTorch versions 2.4.1 and earlier using RemoteModule in distributed computing setups.
Urgency
Critical priority; remote code execution with CVSS 9.8, though disputed as intended functionality.
Action
Upgrade PyTorch to version >2.4.1 or disable RemoteModule deserialization from untrusted sources.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch PyTorch

Get an email when a new PyTorch advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
critical — CVSS 9.8
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-48063

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2024-48063coverage & exploitation statusNVD · CVE.org

More from Microsoft Security Response Center