CVE-2024-45580

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 3, 2025
Updated: Mar 6, 2025
CWE ID 416

Summary

CVE-2024-45580 is a newly disclosed vulnerability that affects the handling of multiple IOCTL (I/O Control) calls from userspace for remote invocation. This issue results in memory corruption, potentially allowing an attacker to execute arbitrary code or cause a denial-of-service condition. An attacker could exploit this vulnerability by sending specifically crafted IOCTL commands to the target system, taking advantage of the memory corruption to gain unauthorized access or cause unexpected behavior. The precise implications and exploitability of this vulnerability are still under investigation by cybersecurity researchers.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share