CVE-2024-49840

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 3, 2025
Updated: Feb 5, 2025
CWE ID 119
CWE ID 823

Summary

CVE-2024-49840 is a newly disclosed vulnerability that affects the handling of IOCTL (Input/Output Control) calls in the validation of FIPS (Federal Information Processing Standards) encryption or decryption functionality. Maliciously crafted IOCTL commands can lead to memory corruption, potentially enabling attackers to execute arbitrary code or cause a denial-of-service condition. This issue poses a significant risk to systems that use FIPS-compliant encryption modules and could lead to serious security consequences if exploited. Users are advised to apply patches or updates as soon as they become available to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share