Intel Ethernet Adapters Vulnerable to Out-of-bounds Write Attack
CVE-2024-23497
8.8HIGH
Key Information:
- Vendor
Intel
- Vendor
- CVE Published:
- 14 August 2024
What is CVE-2024-23497?
A vulnerability exists in the Linux kernel mode driver for various Intel Ethernet Network Controllers and Adapters, which before version 28.3, is susceptible to an out-of-bounds write condition. This flaw may allow an authenticated user with local access to the system to exploit the vulnerability, potentially leading to escalation of privilege and unauthorized control over system resources.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Intel(R) Ethernet Network Controllers and Adapters before version 28.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved