CVE-2024-37025

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Nov 13, 2024
Updated: Nov 15, 2024
CWE ID 279

Summary

CVE-2024-37025 is a recently disclosed vulnerability affecting some versions of Intel(R) Advanced Link Analyzer Standard Edition software installers. This issue stems from incorrect execution-assigned permissions, which could potentially enable an authenticated user to escalate privileges via local access. The vulnerability poses a risk for gaining elevated system access, which could lead to serious consequences such as data theft or system damage. Users are advised to update their software installers as soon as possible to mitigate this risk, as Intel has released a patch for affected versions. This issue underscores the importance of timely software updates and secure privileges to safeguard against potential privilege escalation attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share