Buffer overflow in Intel products - CVE-2024-21859
Published: February 17, 2025
Vulnerability identifier: #VU104009
CSH Severity: Low
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21859
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to a boundary error in the UEFI firmware. A local administrator can trigger memory corruption and gain unauthorized access to sensitive information on the system.
Affected software
UEFI firmware
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
PowerEdge R760xa
Dell XC Core XC760xa
Dell XC Core XC660xs
Dell XC Core XC760
Dell XC Core XC660
PowerEdge XE9640
PowerEdge XE8640
PowerEdge XR7620
PowerEdge XR8620t
PowerEdge XR8610t
PowerEdge XR5610
PowerEdge XE9680
PowerEdge R660
PowerEdge T560
PowerEdge R760xd2
PowerEdge R760xs
PowerEdge R660xs
PowerEdge HS5620
PowerEdge HS5610
PowerEdge R960
PowerEdge R860
PowerEdge MX760c
PowerEdge C6620
PowerEdge R760
Precision 5860 Tower
Precision 7960 Tower
Intel Xeon W2400 processor
Intel Xeon W3400 Processor
APEX Cloud Platform for Microsoft Azure
APEX Cloud Platform for Red Hat OpenShift
Dell Integrated System for Microsoft Azure Stack Hub 16G
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
PowerEdge R760xa
Dell XC Core XC760xa
Dell XC Core XC660xs
Dell XC Core XC760
Dell XC Core XC660
PowerEdge XE9640
PowerEdge XE8640
PowerEdge XR7620
PowerEdge XR8620t
PowerEdge XR8610t
PowerEdge XR5610
PowerEdge XE9680
PowerEdge R660
PowerEdge T560
PowerEdge R760xd2
PowerEdge R760xs
PowerEdge R660xs
PowerEdge HS5620
PowerEdge HS5610
PowerEdge R960
PowerEdge R860
PowerEdge MX760c
PowerEdge C6620
PowerEdge R760
Precision 5860 Tower
Precision 7960 Tower
Intel Xeon W2400 processor
Intel Xeon W3400 Processor
APEX Cloud Platform for Microsoft Azure
APEX Cloud Platform for Red Hat OpenShift
Dell Integrated System for Microsoft Azure Stack Hub 16G
How to mitigate CVE-2024-21859
Install updates from vendor's website.
APEX Cloud Platform for Microsoft Azure - update to 01.05.01.00
Precision 5860 Tower - update to 2.6.1
Precision 7960 Tower - update to 2.6.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.04.01.00
Dell Integrated System for Microsoft Azure Stack Hub 16G - update to 2502
Precision 5860 Tower - update to 2.6.1
Precision 7960 Tower - update to 2.6.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.04.01.00
Dell Integrated System for Microsoft Azure Stack Hub 16G - update to 2502
External References
Related Security Bulletins
- Multiple vulnerabilities in Intel UEFI Firmware
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Dell Client Platform for Intel UPLR3 UEFI firmware
- Multiple vulnerabilities in Dell PowerEdge Server
- Multiple vulnerabilities in Dell Integrated System
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components