CVE-2024-24986
Last modified
CVE-2024-24986 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Ethernet 800 Series Controllers Driver | < 28.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-24986?
How severe is CVE-2024-24986?
How do I fix CVE-2024-24986?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-24978Denial-of-service (DoS) vulnerability exists in TvRock 0.9t8…4.3
- CVE-2024-24980Protection mechanism failure in some 3rd, 4th, and 5th Gener…6.9
- CVE-2024-24981Improper input validation in PfrSmiUpdateFw driver in UEFI f…7.5
- CVE-2024-24983Protection mechanism failure in firmware for some Intel(R) E…7
- CVE-2024-24984Improper input validation for some Intel(R) Wireless Bluetoo…6.8
- CVE-2024-24985Exposure of resource to wrong sphere in some Intel(R) proces…8.5
- CVE-2024-24988Mattermost fails to properly validate the length of the emoj…6.5
- CVE-2024-24989When NGINX Plus or NGINX OSS are configured to use the HTTP/…7.5
- CVE-2024-2499The Squelch Tabs and Accordions Shortcodes plugin for WordPr…6.4
- CVE-2024-24990When NGINX Plus or NGINX OSS are configured to use the HTTP/…7.5
- CVE-2024-24991A Null Pointer Dereference vulnerability in WLAvalancheServi…6.5
- CVE-2024-24992A Path Traversal vulnerability in web component of Ivanti Av…8.8
Are you affected by CVE-2024-24986?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
