CVE-2024-12668
CVSS 3.1 Score 8.2 of 10 (high)
Details
Published Dec 16, 2024
CWE ID 787
Summary
CVE-2024-12668 is a newly discovered vulnerability in Velocidex WinPmem versions prior to 4.1. This issue involves an Out of Bounds Write vulnerability, allowing user space programs to manipulate the driver into writing a 0 into any specified memory location through an IO Control. With this capability, attackers can locate the address of the g_CiOptions global symbol, enabling them to disable signed driver enforcement on the target system and load unsigned drivers.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share