Insufficient Control Flow Management in Virtual RAID on CPU (VROC) - CVE-2024-29079

 

Insufficient Control Flow Management in Virtual RAID on CPU (VROC) - CVE-2024-29079

Published: November 14, 2024


Vulnerability identifier: #VU100473
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-29079
CWE-ID: CWE-691
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient control flow management. A local user can escalate privileges on the target system.


Affected software

Virtual RAID on CPU (VROC)
ThinkSystem SR860 V2
ThinkSystem SR258
ThinkSystem SR530
ThinkSystem SR550
ThinkSystem SR570
ThinkSystem SR590
ThinkSystem SR630 V2
ThinkSystem SR630 V3
ThinkSystem SR650 V2
ThinkSystem SR650 V3
ThinkSystem SR670 V2
ThinkSystem SR850 V2
ThinkSystem SR850 V3
ThinkSystem SR250
ThinkSystem SR860 V3
ThinkSystem ST250
ThinkSystem ST258
ThinkSystem ST50
ThinkSystem ST550
ThinkSystem ST558
ThinkSystem ST58
ThinkSystem ST650 V2
ThinkSystem ST650 V3
ThinkSystem ST658 V2
ThinkSystem ST658 V3
WH5900 Appliance
ThinkServer SR588 V2
System x3550 M5
ThinkAgile HX2720-E Appliance
ThinkAgile HX3720 Appliance
ThinkAgile HX3721 Certified Node
ThinkAgile MX3330-F All-flash Appliance
ThinkAgile MX3330-H Hybrid Appliance
ThinkAgile MX3331-F All-flash Certified node
ThinkAgile MX3331-H Hybrid Certified node
ThinkAgile MX Certified Node – All Flash
ThinkAgile MX Certified Node – Hybrid
ThinkAgile MX1021 on SE350
ThinkServer DN8848 V2
System x3250 M6
ThinkServer SR590 V2
ThinkServer SR590/SR588
ThinkSystem SD530
ThinkSystem SD630 V2
ThinkSystem SD650 V2
ThinkSystem SD650-N V2
ThinkSystem SE350
ThinkSystem SN550
ThinkSystem SN550 V2
ThinkSystem SN850
ThinkSystem SR150
ThinkSystem SR158
Precision 5860 Tower
Precision 7960 Tower
Intel Software Based RAID Windows Utility
Intel Vroc(Rapid Storage Technology enterprise) RAID Driver for Windows 2016/2019 (For Windows)
Precision 7960 Rack

How to mitigate CVE-2024-29079

Install updates from vendor's website.

Virtual RAID on CPU (VROC) - update to 8.6.0.3001
Intel Software Based RAID Windows Utility - update to INTC-LNVGY_DD_SWRAID_VROC.NVME.TSV3-8.6.4.1014-J9VML-0202_WINDOWS_COMP
Intel Vroc(Rapid Storage Technology enterprise) RAID Driver for Windows 2016/2019 (For Windows) - update to INTC-LNVGY_DD_SWRAID_VROC.NVME.TSV3-8.6.4.1014-J9VML-0202_WINDOWS_COMP
Precision 5860 Tower - update to 8.5.0.1593
Precision 7960 Rack - update to 8.5.0.1593
Precision 7960 Tower - update to 8.5.0.1593

External References

Related Security Bulletins