CVE-2024-38257

Severity
7.5HIGH
EPSS
4.3%
top 11.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 10
Latest updateSep 11

Description

Microsoft AllJoyn API Information Disclosure Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages21 packages

NVDmicrosoft/windows< 10.0.14393.7336+3
NVDmicrosoft/windows_10_1607< 10.0.14393.7336
NVDmicrosoft/windows_10_1809< 10.0.17763.6293
NVDmicrosoft/windows_10_21h1< 10.0.19044.4894
NVDmicrosoft/windows_10_22h2< 10.0.19041.4894+1

Patches

🔴Vulnerability Details

2
CVEList
Microsoft AllJoyn API Information Disclosure Vulnerability2024-09-10
GHSA
GHSA-49px-m4gc-wgg2: Microsoft AllJoyn API Information Disclosure Vulnerability2024-09-10

📋Vendor Advisories

1
Microsoft
Microsoft AllJoyn API Information Disclosure Vulnerability2024-09-10

🕵️Threat Intelligence

1
Talos
Vulnerability in Acrobat Reader could lead to remote code execution; Microsoft patches information disclosure issue in Windows API2024-09-11
CVE-2024-38257 (HIGH CVSS 7.5) | Microsoft AllJoyn API Information D | cvebase.io