CVE-2024-52937

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Jan 13, 2025
CWE ID 823

Summary

CVE-2024-52937 is a newly disclosed vulnerability that affects kernel software running inside Guest Virtual Machines (VMs). The issue allows an attacker to write data outside the Guest VM's virtualized GPU memory by exploiting memory shared with the GPU Firmware. This can potentially lead to unauthorized access or privilege escalation within the VM. The exact implications of this vulnerability are still being assessed, but it poses a significant risk to organizations that use virtualized environments with vulnerable software or hardware configurations. Organizations are advised to apply patches or updates as soon as they become available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share