CVE-2024-39251 is a critical vulnerability in the ThundeRobot Control Center v2.0.0.10, specifically within its ControlCenter.sys/ControlCenter64.sys components. This flaw allows unauthenticated attackers to send crafted IOCTL requests, leading to sensitive information disclosure, arbitrary code execution, or privilege escalation. With a CVSS score of 10.0, it represents a severe risk due to its network-based attack vector and low complexity. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion, indicating potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.