CVE-2024-45547

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 6, 2025
Updated: Jan 13, 2025
CWE ID 120

Summary

CVE-2024-45547 is a newly disclosed vulnerability that allows for memory corruption during the processing of an IOCTL (Input/Output Control) call initiated from user-space to verify non-extension FIPS encryption and decryption functionality. This issue can potentially be exploited by attackers to execute arbitrary code or cause denial-of-service conditions, posing a significant security risk. The vulnerability affects certain systems and requires specific conditions to be met for successful exploitation. It is recommended that affected organizations apply patches or mitigations as soon as possible to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share