CVE-2024-20140
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Published Jan 6, 2025
CWE ID 787
Summary
CVE-2024-20140 is a vulnerability affecting Power software that allows for a potential out-of-bounds write due to a missing bounds check. This issue could result in local privilege escalation, granting additional system-level access to malicious actors who have already obtained the System privilege. Notably, user interaction is not required for exploitation. The patch for this vulnerability is identified as ALPS09270402, and its internal reference is MSV-2020.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.