CVE-2024-49837

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 3, 2025
Updated: Feb 5, 2025
CWE ID 129

Summary

CVE-2024-49837 is a newly disclosed vulnerability that affects the suspension process of guest virtual machines. The issue arises due to a memory corruption glitch during the reading of CPU state data. This vulnerability could potentially be exploited to execute arbitrary code within the virtual machine environment, posing a significant threat to data confidentiality and system stability. Successful exploitation could lead to unauthorized access, data theft, or even complete system takeover. VM administrators are strongly advised to apply patches as soon as they become available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share