Potential Escalation of Privilege Vulnerability in Linux kernel Mode Driver
CVE-2024-21807

8.8HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 August 2024

Summary

An improper initialization vulnerability exists in the Linux kernel mode driver for certain Intel Ethernet Network Controllers and Adapters prior to version 28.3. This issue could potentially allow an authenticated user with local access to escalate their privileges on the affected system, creating a security risk that emphasizes the importance of maintaining updated software and implementing strong security practices.

Affected Version(s)

Intel(R) Ethernet Network Controllers and Adapters before version 28.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.