CVE-2024-23376
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Published Oct 7, 2024
Updated: Oct 16, 2024
CWE ID 416
Summary
CVE-2024-23376 is a newly identified memory corruption vulnerability. It affects the handling of the persist buffer command packet in the IOCTL call between user-space and kernel-space. An attacker who can successfully exploit this issue may gain unauthorized control over the system, potentially leading to privilege escalation or denial-of-service attacks. The vulnerability is serious as it can be exploited remotely. Users are advised to update their affected software or hardware components as soon as patches become available to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.