CVE-2024-23942
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Mar 18, 2025
CWE ID 311
Summary
CVE-2024-23942 is a newly disclosed vulnerability that allows a local user to access a configuration file containing sensitive data on a client workstation. The unencrypted data can be exploited by an attacker to impersonate the device or prevent it from accessing cloud services, resulting in a Denial of Service (DoS) attack. This vulnerability highlights the importance of securely storing and encrypting sensitive data, even on local devices. Users are urged to apply patches and update their systems to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.