CVE-2024-45557

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 7, 2025
CWE ID 823

Summary

CVE-2024-45557 is a newly identified vulnerability that affects TME (Trusted Platform Module Extension) software. The issue arises when TME fails to adequately validate addresses in TZ (Trusted Zone) and MPSS (Microsoft Platform Secure Service) requests, leading to memory corruption. Successful exploitation of this vulnerability could result in arbitrary code execution with elevated privileges, posing a significant risk to system security. Organizations are urged to apply available patches or updates as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share