CVE-2024-45396

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 11, 2024
Updated: Nov 12, 2024
CWE ID 617

Summary

CVE-2024-45396 is a denial-of-service vulnerability affecting Quicly, an IETF QUIC protocol implementation. The issue, present in Quicly up to commit d720707, can be exploited by remote attackers to trigger an assertion failure, resulting in a process crash. This vulnerability has been addressed with commit 2a95896104901589c495bc41460262e64ffcad5c. Quicly users are strongly encouraged to update to the latest version to mitigate this risk. This vulnerability could potentially allow attackers to disrupt Quicly services, leading to downtime and potential loss of data for affected organizations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share