CVE-2024-55412

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 7, 2025
Updated: Jan 8, 2025
CWE ID 787

Summary

CVE-2024-55412 is a newly discovered vulnerability affecting the SUNIX Serial Driver x64 version 10.1.0.0 and its associated driver snxpsamd.sys. This issue permits low-privileged users to execute arbitrary Input/Output Control (IOCTL) requests, allowing them to read and write to i/o ports. This vulnerability can be exploited to escalate privileges, execute malicious code with high privileges, and disclose sensitive information. Even more concerning, these signed drivers can be used to bypass Microsoft's driver-signing policy, enabling the deployment of malicious code.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share