CVE-2024-24853: High severity debian/intel-microcode vulnerability
Published Aug 14, 2024
·Updated
Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
1 affected componentFixes available
debian/intel-microcode<=3.20231114.1~deb11u1, <=3.20231114.1~deb12u1
3.20240813.1~deb11u13.20240813.1~deb12u13.20240813.2
Remediation
Event History
Aug 14, 2024
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Sep 17, 2024
Data Sourced
via Ubuntu·12:19 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24853?
The severity of CVE-2024-24853 is categorized as high due to its potential to enable privilege escalation.
2
How do I fix CVE-2024-24853?
To fix CVE-2024-24853, update the intel-microcode package to version 3.20240813.1~deb11u1 or later.
3
Who is affected by CVE-2024-24853?
CVE-2024-24853 affects systems using certain versions of Intel processors with the intel-microcode package on Debian.
4
What should I do if I cannot update my system for CVE-2024-24853?
If unable to update, limit physical access to the system to mitigate the risk associated with CVE-2024-24853.
5
Is CVE-2024-24853 exploited in the wild?
As of now, there is no public indication that CVE-2024-24853 is actively exploited in the wild.