CVE-2024-20140

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Jan 6, 2025
CWE ID 787

Summary

CVE-2024-20140 is a vulnerability affecting Power software that allows for a potential out-of-bounds write due to a missing bounds check. This issue could result in local privilege escalation, granting additional system-level access to malicious actors who have already obtained the System privilege. Notably, user interaction is not required for exploitation. The patch for this vulnerability is identified as ALPS09270402, and its internal reference is MSV-2020.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share