Skip to content
COOEY

EXPOSURES › CVE-2024-1086

CVE-2024-1086

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-05-30 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-1086 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatched

A use-after-free vulnerability in the Linux kernel's netfilter component allows local privilege escalation and has been actively exploited in the wild.

This Linux kernel vulnerability enables local privilege escalation, meaning an attacker with local access can escalate to root. DIB organizations must ensure their Linux systems are patched against this actively exploited CVE, as it represents a critical failure in the supply chain and ongoing maintenance of foundational OS components. Failure to patch exposes systems to ransomware and further compromise.

Shame score — The Linux kernel is a foundational component shipped by major vendors; a critical, actively exploited vulnerability in its core networking stack demonstrates severe negligence in patching and supply chain security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.