
Public Disclosure of CVE-2024-10930
Public Disclosure of CVE-2024-10930
Date: [12-02-2025]
A vulnerability was identified in Carrier product E20-BLK416X.EXE version 4.16, which could allow local privilege escalation. This issue has been assigned the identifier [CVE-2024-10930] .The vendor will release an advisory with further details and remediation steps.
Carrier was informed about the issue in Block Load software that could potentially allow execution of arbitrary code when running Block Load installer (E20-BLK416X.EXE). A successful attempt would require the local user having downloaded or otherwise placed, a malicious binary application in the same directory as installer binary and then running the installer.
If successful, the attackers code would execute with the elevated privileges of the application.
It is strongly recommended that users of the affected products take the following actions:
This vulnerability was discovered by Sahil Shah, Shaurya & Shuvro and we thank the vendor, Carrier, for their co-operation in releasing a patch.
If you have any questions or need more information, feel free to reach out at [[email protected]] & Linkedin