CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-21807

CVSS 9.3v4.0pub. 2024-08-14upd. 2026-04-15

Improper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

🤖 AI Analysis
How it works

The vulnerability is an improper initialization (CWE-665) in the Linux kernel mode driver supporting selected Intel Ethernet controllers and adapters. Improper initialization can lead to inadequate privilege management (CWE-269), which a local authenticated user can exploit to gain elevated privileges on the system. The attack requires local access but does not require interaction from other users or special prerequisites beyond a basic user account.

Impact

An authenticated local user can achieve privilege escalation, potentially gaining full control over the operating system and affecting the security and availability of the environment in which the vulnerable driver operates.

Mitigation & patch

The driver for Intel Ethernet network controllers and adapters should be updated to version 28.3 or later. Detailed information about available patches can be found in the official Intel security advisory: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html

Who is affected

Linux kernel mode driver for selected Intel Ethernet network controllers and adapters in versions prior to 28.3.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References