CVE-2024-23497

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Aug 14, 2024
Updated: Sep 12, 2024
CWE ID 787

Summary

CVE-2024-23497 is a vulnerability affecting some Intel(R) Ethernet Network Controllers and Adapters before version 28.3. This issue involves an out-of-bounds write in Linux kernel mode, enabling a authenticated user to potentially escalate privileges through local access. The vulnerability could lead to serious security consequences if exploited successfully. The Linux kernel mode driver is responsible for this occurrence, and Intel has released a patch to address the issue. It is recommended that users update their drivers to ensure protection against this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share