CVE-2024-21944 MEDIUM

CVE-2024-21944

Weakness CWE-20 · Input validation
Published June 10, 2026
Last update June 11, 2026

CVSS base score

5.3/10
Attack vector Local
Attack complexity High
Privileges required High
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N

What the vulnerability does

01Description

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrity.

Key dates

02Disclosure timeline

June 10, 2026 CVE published
June 11, 2026 Record updated