Faronics Deep Freeze Vulnerable to Out-of-Bounds Read Vulnerability
CVE-2024-8159

6.4MEDIUM

Key Information:

Vendor

Faronics

Vendor
CVE Published:
3 October 2024

What is CVE-2024-8159?

The out-of-bounds read vulnerability in Deep Freeze version 9.00.020.5760 allows attackers to exploit the system by triggering the 0x70014 IOCTL code of the FarDisk.sys driver. This could enable unauthorized access to sensitive data or lead to unpredictable system behavior. Users of the affected version should review their security measures and consider updates or mitigations to protect against potential exploitation of this vulnerability.

Affected Version(s)

DeepFreeze Windows 9.00.020.5760

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-8159 : Faronics Deep Freeze Vulnerable to Out-of-Bounds Read Vulnerability