CVE-2024-1086 Vulnerability: Critical Privilege Escalation Flaw in Linux Kernel Exploited in the Ransomware Attacks
ID: 9d5cd14b-6c70-57df-8d23-cbb3e8eb422c
STIX ID: report--9d5cd14b-6c70-57df-8d23-cbb3e8eb422c
Feed Name: SOC Prime Blog
CISA confirmed active exploitation of CVE-2024-1086, a critical use-after-free in the Linux kernel netfilter (CVSS 7.8) that allows local attackers to escalate to root and has a public PoC; threat actors are leveraging it in ransomware campaigns to disable protections, move laterally, and establish persistence. Organizations are advised to patch affected kernels, apply mitigations such as disabling unprivileged namespace creation (kernel.unprivileged_userns_clone=0), and verify deployment across Linux estates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
