CVE-2024-33061

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 6, 2025
Updated: Jan 10, 2025
CWE ID 125
CWE ID 126

Summary

CVE-2024-33061 is a newly disclosed vulnerability that allows for information disclosure during the processing of an IOCTL (Input/Output Control) call. This call can occur when releasing a trusted VM process or opening a channel without proper initialization. As a result, sensitive information could be exposed to unauthorized parties. This vulnerability poses a risk to system security and confidentiality. The impact of this issue can be mitigated by applying relevant patches or implementing access control measures to limit unauthorized access to the affected system components.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share