CVE-2024-20096

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Oct 7, 2024
Updated: Oct 27, 2024
CWE ID 125

Summary

CVE-2024-20096 is a newly disclosed vulnerability affecting the m4u parser. This issue involves a missing bounds check that allows for an out-of-bounds read. The consequence of this vulnerability is local information disclosure, and it requires System execution privileges to exploit it. User interaction is not necessary for an attacker to take advantage of this flaw. The patch for this vulnerability is identified as ALPS08996900, and its Mitre ID is MSV-1635.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share