cbcvebase.
CVE-2024-21323
published 2024-04-09

CVE-2024-21323: Microsoft Defender for IoT Remote Code Execution Vulnerability

PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.20%
86.7th percentile
Microsoft Defender for IoT Remote Code Execution Vulnerability

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftdefender_for_iot< 24.1.324.1.3
microsoftmicrosoft_defender_for_iot>= 22.0.0 < 24.1.324.1.3
msrcmicrosoft_defender_for_iot

Detection & IOCsextracted from sources · hover to see the quote

filenametar file (malicious update package)
  • Detect path traversal attempts via malicious tar file uploads sent to the Defender for IoT sensor update endpoint, particularly unsigned update packages.
  • Monitor for unexpected file overwrites on Defender for IoT sensor hosts, which may indicate successful exploitation of the path traversal vulnerability.
  • Alert on low-privileged authenticated users initiating the update process on Defender for IoT sensors, especially if followed by unsigned package delivery.
  • ·Exploitation requires the attacker to be authenticated with at least low-level privileges (sufficient to initiate the update process) on the Defender for IoT sensor — unauthenticated exploitation is not possible for this CVE.
  • ·Patched version is 24.1.3 or above; sensors running older versions remain vulnerable.
  • ·As of the advisory publication, the vulnerability had not been publicly exploited in the wild (Exploited: No, Publicly Disclosed: No).

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.