Buffer overflow in Intel products - CVE-2024-21859

 

Buffer overflow in Intel products - CVE-2024-21859

Published: February 17, 2025


Vulnerability identifier: #VU104009
CSH Severity: Low
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21859
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to a boundary error in the UEFI firmware. A local administrator can trigger memory corruption and gain unauthorized access to sensitive information on the system.


Affected software

UEFI firmware
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
PowerEdge R760xa
Dell XC Core XC760xa
Dell XC Core XC660xs
Dell XC Core XC760
Dell XC Core XC660
PowerEdge XE9640
PowerEdge XE8640
PowerEdge XR7620
PowerEdge XR8620t
PowerEdge XR8610t
PowerEdge XR5610
PowerEdge XE9680
PowerEdge R660
PowerEdge T560
PowerEdge R760xd2
PowerEdge R760xs
PowerEdge R660xs
PowerEdge HS5620
PowerEdge HS5610
PowerEdge R960
PowerEdge R860
PowerEdge MX760c
PowerEdge C6620
PowerEdge R760
Precision 5860 Tower
Precision 7960 Tower
Intel Xeon W2400 processor
Intel Xeon W3400 Processor
APEX Cloud Platform for Microsoft Azure
APEX Cloud Platform for Red Hat OpenShift
Dell Integrated System for Microsoft Azure Stack Hub 16G

How to mitigate CVE-2024-21859

Install updates from vendor's website.

APEX Cloud Platform for Microsoft Azure - update to 01.05.01.00
Precision 5860 Tower - update to 2.6.1
Precision 7960 Tower - update to 2.6.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.04.01.00
Dell Integrated System for Microsoft Azure Stack Hub 16G - update to 2502

External References

Related Security Bulletins