CVE-2024-38660
CVSS 3.1 Score 3.8 of 10 (low)
Details
Published Nov 13, 2024
Updated: Nov 15, 2024
CWE ID 693
Summary
CVE-2024-39285 is a newly identified vulnerability affecting certain Intel(R) Server M20NTP Family UEFI firmware. The issue involves improper access control that could allow a privileged user, through local access, to potentially disclose sensitive information. This vulnerability may pose a risk to system security and confidentiality. Intel is advising users to apply the forthcoming security update to mitigate this issue. Until then, it's recommended to limit access to the affected systems and implement additional security measures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.