NA

CVE-2024-30078

Published: 11/06/2024 Updated: 21/06/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Windows Wi-Fi Driver Remote Code Execution Vulnerability

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows server 2012 r2

microsoft windows server 2008 r2

microsoft windows server 2012 -

microsoft windows server 2008 -

microsoft windows server 2022

microsoft windows 10 1809

microsoft windows server 2019

microsoft windows 11 22h2

microsoft windows 11 21h2

microsoft windows server 2022 23h2

microsoft windows 11 23h2

microsoft windows 10 1507

microsoft windows 10 1607

microsoft windows 10 22h2

microsoft windows 10 21h2

microsoft windows server 2016

Github Repositories

CVE-2024-30078 Detection and Command Execution Script

CVE-2024-30078 Detection and Command Execution Script This project contains a NASL script that detects the CVE-2024-30078 vulnerability and executes a specified command if the target is vulnerable The script is designed to work with the Nessus tool, automatically handling target IP addresses and ports provided by Nessus during a scan Cyber Security Consultant Alperen Ugurlu

CVE-2024-30078 Detection and Command Execution Script

CVE-2024-30078 Detection and Command Execution Script This project contains a NASL script that detects the CVE-2024-30078 vulnerability and executes a specified command if the target is vulnerable The script is designed to work with the Nessus tool, automatically handling target IP addresses and ports provided by Nessus during a scan Cyber Security Consultant Alperen Ugurlu

edgedressing leverages a Windows "feature" in order to force a target's Edge browser to open. This browser is then directed to a URL of choice.

edgedressing One day while experimenting with airpwn-ng, I noticed unexpected GET requests on the target node The node in question happened to be a Windows 10 laptop and every time it would connect to the AP a GET request was made Using scapy I was able to make the Edge browser open up and proceed to a URL of my choosing upon connecting to a wireless access point NCSI fun

Recent Articles

Let's kick off our summer with a pwn-me-by-Wi-Fi bug in Microsoft Windows
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Redmond splats dozens of bugs as does Adobe while Arm drivers and PHP under active attack

Patch Tuesday Microsoft kicked off our summer season with a relatively light June Patch Tuesday, releasing updates for 49 CVE-tagged security flaws in its products – including one bug deemed critical, a fairly terrifying one in wireless networking, and one listed as publicly disclosed. The one that's listed as publicly known, and not yet publicly exploited, is CVE-2023-50868 in Windows Server as well as non-Microsoft software. It's a vulnerability in DNSSEC implementations that we've known abo...