Foxboro Sys Faces Local Denial-of-Service and Privilege Escalation Vulnerability
CVE-2024-5681
7.8HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 11 July 2024
What is CVE-2024-5681?
An improper input validation vulnerability in the Foxboro.sys driver can enable a local user with malicious intent to craft a script or program that exploits the vulnerability through an IOCTL call. This exploitation may lead to local denial-of-service, privilege escalation, and even potential kernel execution. The flaw poses a risk to users with local access, emphasizing the need for immediate action and remediation. Users are advised to review Schneider Electric's security notice for guidelines on mitigating potential impacts.
Affected Version(s)
EcoStruxure Foxboro DCS Core Control Services Versions 9.8 and prior