CVE-2024-20110
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Published Nov 4, 2024
CWE ID 787
Summary
CVE-2024-20110 is a newly disclosed vulnerability affecting the ccu software. This issue involves a missing bounds check, resulting in a possible out-of-bounds write. An attacker who exploits this flaw can achieve local privilege escalation with System execution privileges. Importantly, user interaction is not required for exploitation. The patch for this vulnerability is identified as ALPS09065887, and it is recommended that affected systems be updated to address this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share