CVE-2024-21975

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 15, 2024
CWE ID 20

Summary

CVE-2024-21975 is a newly disclosed cybersecurity vulnerability that affects the NPU (Neural Processing Unit) driver. The issue lies in the driver's input validation mechanism, which is found to be insufficient. An attacker can exploit this defect by providing a maliciously crafted pointer, potentially triggering arbitrary code execution. Consequently, an unauthorized user could gain elevated system privileges and execute malicious commands, posing a significant threat to system security. Users are recommended to update their drivers as soon as patches become available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share