CVE-2024-45584

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 3, 2025
Updated: Feb 5, 2025
CWE ID 119
CWE ID 822

Summary

CVE-2024-45584 is a newly identified vulnerability affecting certain operating systems. This issue stems from a compatibility IOCTL call being followed improperly by a normal IOCTL call from userspace, resulting in memory corruption. An attacker could exploit this vulnerability by crafting specific inputs that trigger the memory corruption, potentially gaining unauthorized access or executing arbitrary code. Systems that have not applied the relevant patches are at risk. It is recommended that affected organizations prioritize applying the necessary updates to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share