#VU100574 Exposure of Resource to Wrong Sphere in Intel products - CVE-2024-24985
Published: November 18, 2024
Vulnerability identifier: #VU100574
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-24985
CWE-ID: CWE-668
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Intel Alias Checking Trusted Module (ACTM)
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
Intel Alias Checking Trusted Module (ACTM)
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
Software vendor:
Intel
Intel
Description
The vulnerability allows a local user to compromise the system.
The vulnerability exists due to exposure of resource to wrong sphere. A local administrator can gain elevated privileges on the target system.
Remediation
Install updates from vendor's website.