CVE-2024-45548

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 6, 2025
Updated: Jan 13, 2025
CWE ID 125
CWE ID 126

Summary

CVE-2024-45548 is a newly disclosed vulnerability that affects the FIPS encryption or decryption validation functionality of a specific system. This issue results in memory corruption during the processing of IOCTL (Input/Output Control) calls. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code or cause a denial-of-service condition. The exact cause of the memory corruption and the required attacker privileges are not yet clear. Users are advised to apply the forthcoming patch as soon as it becomes available to mitigate the risk of potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share