CVE-2024-45396
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-45396 is a denial-of-service vulnerability affecting Quicly, an IETF QUIC protocol implementation. The issue, present in Quicly up to commit d720707, can be exploited by remote attackers to trigger an assertion failure, resulting in a process crash. This vulnerability has been addressed with commit 2a95896104901589c495bc41460262e64ffcad5c. Quicly users are strongly encouraged to update to the latest version to mitigate this risk. This vulnerability could potentially allow attackers to disrupt Quicly services, leading to downtime and potential loss of data for affected organizations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.