CVE-2024-29214

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 12, 2025
CWE ID 20

Summary

CVE-2024-29214 is a vulnerability affecting UEFI firmware CseVariableStorageSmm on certain Intel processors. The issue involves improper input validation, which could enable a privileged user to potentially escalate their privileges through local access. This vulnerability poses a risk if exploited, as it could allow an attacker to gain higher system access and potentially cause significant damage. Intel has not yet released a patch for this issue, leaving affected systems vulnerable until a solution is provided. Users are advised to exercise caution and implement additional security measures until a fix is available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share