Use-after-free in Open Management Infrastructure and Microsoft System Center Operations Manager - CVE-2024-21334
Published: March 12, 2024
Vulnerability identifier: #VU87373
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21334
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in the Open Management Infrastructure (OMI). A remote attacker can execute arbitrary code on the target system.
Affected software
Open Management Infrastructure
Microsoft System Center Operations Manager
IBM Qradar SIEM
Microsoft System Center Operations Manager
IBM Qradar SIEM
How to mitigate CVE-2024-21334
Install updates from vendor's website.