CVE-2024-10972

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Dec 16, 2024
CWE ID 20

Summary

CVE-2024-10972 is a vulnerability affecting Velocidex WinPmem versions 4.1 and below. An attacker with admin access can exploit this Improper Input Validation issue, leading to a Blue Screen of Death (BSOD). The vulnerability stems from verification checks being performed only at the beginning of the routine, allowing unauthorized modifications to memory access rights. A temporary workaround involves implementing a rule to restrict unauthorized loading of WinPmem outside of incident response operations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share