CVE-2024-20097

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Oct 7, 2024
Updated: Oct 10, 2024
CWE ID 125

Summary

CVE-2024-20097 identifies a vulnerability in the vdec component, which is susceptible to an out-of-bounds read due to inadequate bounds checking. This issue affects certain products, including lAMRr5 and sYyJE8, and can result in local information disclosure if exploited, requiring system execution privileges. Notably, user interaction is not necessary for exploitation, making it easier for attackers to access sensitive information. The vulnerability has been rated with a medium severity score of 4.4 and poses a confidentiality impact rated as high. To remediate this vulnerability, users are advised to apply the patch identified as ALPS09028313.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share