Foxboro.sys Out-of-Bounds Write Vulnerability Could Lead to Local Denial-of-Service or Kernel Memory Leak
CVE-2024-5679
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 11 July 2024
What is CVE-2024-5679?
An out-of-bounds write vulnerability exists in the Foxboro.sys driver, allowing local users to exploit the flaw by crafting a malicious script or program that utilizes an IOCTL call. This exploitation can lead to local denial-of-service attacks or unintentional leakage of kernel memory. The vulnerability poses a significant risk, particularly in environments where the Foxboro.sys driver is deployed, as it permits unauthorized actions that can compromise system stability and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EcoStruxure Foxboro DCS Core Control Services Versions 9.8 and prior
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved