CVE-2024-45819
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Dec 19, 2024
Updated: Dec 31, 2024
CWE ID 276
Summary
CVE-2024-45819 is a vulnerability affecting PVH guests where ACPI tables are constructed by the toolstack. During this process, local memory is used to build the tables, which are later copied into guest memory. Although used parts of the local memory are properly filled in, the excess allocated space retains its previous contents, potentially exposing sensitive information to attackers. This issue could lead to unauthorized access or privilege escalation within the virtual environment.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.