CVE-2024-38412
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Feb 3, 2025
Updated: Feb 5, 2025
CWE ID 416
Summary
CVE-2024-38412 is a newly disclosed cybersecurity vulnerability that affects the handling of IOCTL (I/O Control) calls from user-space to kernel-space for session error processing. The issue results in memory corruption, potentially enabling attackers to execute arbitrary code in the kernel or cause denial-of-service conditions. Exploitation of this vulnerability requires local access or specially crafted input. Users and organizations are advised to apply patches as soon as they become available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share