CVE-2024-26507: Finalwire AIDA64 Business

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit through 7.00.6742 allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components.

Affected products

  • Finalwire AIDA64 Business: up to and including 7.00.6700
  • Finalwire AIDA64 Engineer: up to and including 7.00.6700
  • Finalwire AIDA64 Network Audit: up to and including 7.00.6700
  • Finalwire Airda Extreme: up to and including 7.00.6700

Published 2024-06-10. Last modified 2026-10-09.