CVE-2024-30078
published 2024-06-11CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution Vulnerability
PriorityP357high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
5.16%
91.5th percentile
Windows Wi-Fi Driver Remote Code Execution Vulnerability
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20680 | 10.0.10240.20680 |
| microsoft | windows_10_1607 | < 10.0.14393.7070 | 10.0.14393.7070 |
| microsoft | windows_10_1809 | < 10.0.17763.5936 | 10.0.17763.5936 |
| microsoft | windows_10_21h2 | < 10.0.19044.4529 | 10.0.19044.4529 |
| microsoft | windows_10_22h2 | < 10.0.19045.4529 | 10.0.19045.4529 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20680 | 10.0.10240.20680 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.7070 | 10.0.14393.7070 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.5936 | 10.0.17763.5936 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5936 | 10.0.17763.5936 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.4529 | 10.0.19044.4529 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4529 | 10.0.19045.4529 |
| microsoft | windows_11_21h2 | < 10.0.22000.3019 | 10.0.22000.3019 |
| microsoft | windows_11_22h2 | < 10.0.22621.3737 | 10.0.22621.3737 |
| microsoft | windows_11_23h2 | < 10.0.22631.3737 | 10.0.22631.3737 |
| microsoft | windows_11_version_21h2 | >= 10.0.22000.0 < 10.0.22000.3019 | 10.0.22000.3019 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3737 | 10.0.22621.3737 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3737 | 10.0.22631.3737 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3737 | 10.0.22631.3737 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27170 | 6.1.7601.27170 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.22720 | 6.0.6003.22720 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.24919 | 6.2.9200.24919 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22023 | 6.3.9600.22023 |
| microsoft | windows_server_2016 | < 10.0.14393.7070 | 10.0.14393.7070 |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector is adjacent network (AV:A) — attacker must be within Wi-Fi radio proximity of the target to send the malicious packet; detection should focus on anomalous 802.11 frames or unexpected Wi-Fi driver activity from nearby devices. ↗
- →The exploit vector is a malicious networking packet sent to a system with a Wi-Fi networking adapter — monitor for malformed or unexpected low-level Wi-Fi frames targeting Windows hosts. ↗
- →No authentication is required to exploit this vulnerability — any unauthenticated device on the same wireless network segment is a potential threat source. ↗
- ·Exploitation is rated 'Less Likely' by Microsoft for the latest software release, and as of the advisory there is no public exploit or confirmed in-the-wild exploitation. ↗
- ·The vulnerability is constrained to the local wireless network segment — remote internet-based exploitation is not possible without prior physical/network proximity. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Wi-Fi Driver Remote Code Execution Vulnerability
vendor_msrc·2024-06-11·CVSS 8.8
CVE-2024-30078 [HIGH] CWE-20 Windows Wi-Fi Driver Remote Code Execution Vulnerability
Windows Wi-Fi Driver Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
Exploiting this vulnerability requires an attacker to be within proximity of the target system to send and receive radio transmissions.
FAQ: How could an attacker exploit the vulnerability?
An unauthenticated attacker could send a malicious networking packet to an adjacent system that is employing a Wi-Fi networking adapter, which could enable remote code execution.
Windows Wi-Fi Driver: Windows Wi-Fi Driver
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://catalo
GHSA
GHSA-c6jw-39ph-m4hq: Windows Wi-Fi Driver Remote Code Execution Vulnerability
ghsa_unreviewed·2024-06-11
CVE-2024-30078 [HIGH] CWE-20 GHSA-c6jw-39ph-m4hq: Windows Wi-Fi Driver Remote Code Execution Vulnerability
Windows Wi-Fi Driver Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Qualys
Mitigate High-Risk Vulnerabilities Using TruRisk | Qualys
blogs_qualys·2024-12-04·CVSS 7.5
CVE-2013-2900 [HIGH] Mitigate High-Risk Vulnerabilities Using TruRisk | Qualys
#### Table of Contents
- TruRisk Mitigate: A Flexible Approach to Vulnerability Management
- Managing CVE-2013-2900: WinVerifyTrust Signature Validation Vulnerability
- Mitigating CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution Vulnerability
- Managing needrestart Vulnerabilities: Addressing Local Privilege Escalation (LPE) Risks
- Key Benefits of TruRisk Mitigate
- Strengthening Security with TruRisk Mitigate
In late 2024, organizations faced over 65 million detections from three critical vulnerabilities—CVE-2013-2900, CVE-2024-38122, and CVE-2024-30078—underscoring the urgent need for proactive vulnerability management. Adding to these challenges, the Qualys Threat Research Unit (TRU) uncovered five Local Privilege Escalation (LPE) vulnerabilities in November within the need
Qualys
Proactively Managing High-Risk Vulnerabilities with TruRisk Mitigate™
blogs_qualys·2024-12-04·CVSS 7.5
CVE-2013-2900 [HIGH] Proactively Managing High-Risk Vulnerabilities with TruRisk Mitigate™
## Table of Contents
TruRisk Mitigate: A Flexible Approach to Vulnerability Management
Managing CVE-2013-2900: WinVerifyTrust Signature Validation Vulnerability
Mitigating CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution Vulnerability
Managing needrestart Vulnerabilities: Addressing Local Privilege Escalation (LPE) Risks
Key Benefits of TruRisk Mitigate
Strengthening Security with TruRisk Mitigate
In late 2024, organizations faced over 65 million detections from three critical vulnerabilities—CVE-2013-2900, CVE-2024-38122, and CVE-2024-30078—underscoring the urgent need for proactive vulnerability management. Adding to these challenges, the Qualys Threat Research Unit (TRU) uncovered five Local Privilege Escalation (LPE) vulnerabilities in November within the needrestart u
Trendmicro
The June 2024 Security Update Review
blogs_trendmicro·2024-06-11
The June 2024 Security Update Review
# The June 2024 Security Update Review
Get the June 2024 security update and review.
By: Dustin Childs
2024/06/11
Read time: ( words)
Save to Folio
Somehow, we’ve made it to the sixth patch Tuesday of 2024, and Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for June 2024
For June, Adobe released 10 patches addressing 165(!) CVEs in Adobe Cold Fusion, Photoshop, Experience Manager, Audition, Media Encoder, FrameMaker Publishing Server, Adobe Commerce, Substance 3D Stager, Creative Cloud Desktop, and Acrobat Android. The fix for Experience Ma
Talos
Only one critical issue disclosed as part of Microsoft Patch Tuesday
blogs_talos·2024-06-11·CVSS 8.0
CVE-2024-30080 [HIGH] Only one critical issue disclosed as part of Microsoft Patch Tuesday
Microsoft released its monthly security update Tuesday, disclosing 49 vulnerabilities across its suite of products and software.
Of those there is only one critical vulnerability. Every other security issues disclosed this month is considered "important."
The lone critical security issue is CVE-2024-30080, a remote code execution vulnerability due to a use-after-free (UAF) issue in the HTTP handling function of Microsoft Message Queuing (MSMQ) messages.
An adversary can send a specially crafted malicious MSMQ packet to an MSMQ server, potentially allowing them to perform remote code execution on the server side. Microsoft considers this vulnerability “more likely” to be exploited.
There is also a remote code execution vulnerability in Microsoft Outlook, CVE-2024-30103. By successfully
Trendmicro
The June 2024 Security Update Review
blogs_trendmicro·2024-06-11
The June 2024 Security Update Review
## The June 2024 Security Update Review
Get the June 2024 security update and review.
By: Dustin Childs 2024/06/11 Read time: ( words)
Save to Folio
Somehow, we’ve made it to the sixth patch Tuesday of 2024, and Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for June 2024
For June, Adobe released 10 patches addressing 165(!) CVEs in Adobe Cold Fusion, Photoshop, Experience Manager, Audition, Media Encoder, FrameMaker Publishing Server, Adobe Commerce, Substance 3D Stager, Creative Cloud Desktop, and Acrobat Android. The fix for Experience Ma
Talos
Only one critical issue disclosed as part of Microsoft Patch Tuesday
blogs_talos·2024-06-11·CVSS 8.0
CVE-2024-30080 [HIGH] Only one critical issue disclosed as part of Microsoft Patch Tuesday
## Only one critical issue disclosed as part of Microsoft Patch Tuesday
Microsoft released its monthly security update Tuesday, disclosing 49 vulnerabilities across its suite of products and software.
Of those there is only one critical vulnerability. Every other security issues disclosed this month is considered "important."
The lone critical security issue is CVE-2024-30080 , a remote code execution vulnerability due to a use-after-free (UAF) issue in the HTTP handling function of Microsoft Message Queuing (MSMQ) messages.
An adversary can send a specially crafted malicious MSMQ packet to an MSMQ server, potentially allowing them to perform remote code execution on the server side. Microsoft considers this vulnerability “more likely” to be exploited.
There is also a remote code exec
Krebs
Patch Tuesday, June 2024 “Recall” Edition
blogs_krebs·2024-06-11
Patch Tuesday, June 2024 “Recall” Edition
Microsoft today released updates to fix more than 50 security vulnerabilities in Windows and related software, a relatively light Patch Tuesday this month for Windows users. The software giant also responded to a torrent of negative feedback on a new feature of Redmond’s flagship operating system that constantly takes screenshots of whatever users are doing on their computers, saying the feature would no longer be enabled by default.
Last month, Microsoft debuted Copilot+ PCs, an AI-enabled version of Windows. Copilot+ ships with a feature nobody asked for that Redmond has aptly dubbed Recall, which constantly takes screenshots of what the user is doing on their PC. Security experts roundly trashed Recall as a fancy keylogger, noting that it would be a gold mine of information for attacke
Krebs
Patch Tuesday, June 2024 “Recall” Edition
blogs_krebs·2024-06-11
Patch Tuesday, June 2024 “Recall” Edition
Microsoft today released updates to fix more than 50 security vulnerabilities in Windows and related software, a relatively light Patch Tuesday this month for Windows users. The software giant also responded to a torrent of negative feedback on a new feature of Redmond’s flagship operating system that constantly takes screenshots of whatever users are doing on their computers, saying the feature would no longer be enabled by default.
Last month, Microsoft debuted Copilot+ PCs , an AI-enabled version of Windows. Copilot+ ships with a feature nobody asked for that Redmond has aptly dubbed Recall , which constantly takes screenshots of what the user is doing on their PC. Security experts roundly trashed Recall as a fancy keylogger, noting that it would be a gold mine of information for attac
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30078https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30078https://www.vicarius.io/vsociety/posts/cve-2024-30078-detection-script-windows-wi-fi-driver-remote-code-execution-vulnerabilityhttps://www.vicarius.io/vsociety/posts/cve-2024-30078-mitigation-script-windows-wi-fi-driver-remote-code-execution-vulnerability
2024-06-11
Published