CVE Vulnerabilities

CVE-2024-37973

Uncontrolled Recursion

Published: Jul 09, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Secure Boot Security Feature Bypass Vulnerability

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

NameVendorStart VersionEnd Version
Windows_10_1507Microsoft*10.0.10240.20710 (excluding)
Windows_10_1607Microsoft*10.0.14393.7159 (excluding)
Windows_10_1809Microsoft*10.0.17763.6054 (excluding)
Windows_10_21h2Microsoft*10.0.19044.4651 (excluding)
Windows_10_22h2Microsoft*10.0.19045.4651 (excluding)
Windows_11_21h2Microsoft*10.0.22000.3079 (excluding)
Windows_11_22h2Microsoft*10.0.22621.3880 (excluding)
Windows_11_23h2Microsoft*10.0.22631.3880 (excluding)
Windows_server_2012Microsoft- (including)- (including)
Windows_server_2012Microsoftr2 (including)r2 (including)
Windows_server_2016Microsoft*10.0.14393.7159 (excluding)
Windows_server_2019Microsoft*10.0.17763.6054 (excluding)
Windows_server_2022Microsoft*10.0.20348.2582 (excluding)
Windows_server_2022_23h2Microsoft*10.0.25398.1009 (excluding)

Potential Mitigations

References