Potential Escalation of Privilege via Local Access
CVE-2024-21810
8.8HIGH
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 14 August 2024
Summary
A flaw exists in the Linux kernel mode driver for Intel Ethernet Network Controllers and Adapters, which may lead to improper input validation. This vulnerability allows authenticated users with local access the potential to escalate their privileges. The affected products are those that have not been updated to version 28.3, which may leave systems open to risks associated with unauthorized access and privilege escalation.
Affected Version(s)
Intel(R) Ethernet Network Controllers and Adapters before version 28.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved