CVE-2024-41167

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 13, 2024
Updated: Nov 15, 2024
CWE ID 20

Summary

CVE-2024-41167 is a vulnerability affecting certain Intel(R) Server Board M10JNP2SB Family UEFI firmware. The issue stems from insufficient input validation, which could potentially enable a privileged user to escalate their access locally. This vulnerability may pose a serious risk, as UEFI firmware is a crucial part of a system's boot process and grants low-level access to hardware. Users are advised to apply the available patches or updates to mitigate this vulnerability and protect their systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share