cbcvebase.
CVE-2024-29053
published 2024-04-09

CVE-2024-29053: Microsoft Defender for IoT Remote Code Execution Vulnerability

PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.20%
86.6th percentile
Microsoft Defender for IoT Remote Code Execution Vulnerability

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftdefender_for_iot< 24.1.324.1.3
microsoftmicrosoft_defender_for_iot>= 22.0.0 < 24.1.324.1.3
msrcmicrosoft_defender_for_iot

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2024-29053 is a path traversal vulnerability exploited via the file upload feature of Microsoft Defender for IoT; monitor for unexpected file uploads to sensitive server locations, especially from low-privileged authenticated users or users with access to a matching private key.
  • Successful exploitation allows overwriting arbitrary files on the Defender for IoT server appliance, including sensitive ones; alert on unexpected file modifications in sensitive directories on the sensor/appliance.
  • Exploitation requires either an administrative account in the Defender for OT web application or an authorized user with access to a private key matching a public key already present on the server; audit privileged accounts and key material on Defender for IoT appliances.
  • The attack vector is unauthenticated file upload to sensitive server paths per the CrowdStrike description (CVSS PR:L per MSRC); monitor Defender for IoT web application upload endpoints for path traversal sequences (e.g., '../') in filenames or upload paths.
  • ·Patch to Defender for IoT version 24.1.3 or above to remediate; unpatched versions are vulnerable to this path traversal RCE.
  • ·MSRC classifies exploitation as 'Less Likely' and the vulnerability has not been publicly exploited or disclosed as of the advisory date; however, the file-upload path traversal primitive is straightforward and warrants prompt patching.
  • ·There is a discrepancy between sources: CrowdStrike describes the attacker as 'unauthenticated', while MSRC states privileges required is Low (PR:L), meaning some form of authenticated/authorized access is needed. Treat the MSRC description as authoritative.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.