Potential Escalation of Privilege via Local Access in Linux Kernel Mode Driver
CVE-2024-24986
8.8HIGH
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 14 August 2024
Summary
The vulnerability originates from improper access control in the Linux kernel mode driver for specific Intel Ethernet Network Controllers and Adapters prior to version 28.3. This flaw could be exploited by an authenticated user, allowing for potential escalation of privilege through local access. Organizations utilizing affected products should implement necessary mitigations and updates to safeguard against unauthorized access and enhance overall system security.
Affected Version(s)
Intel(R) Ethernet Network Controllers and Adapters before version 28.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved