CVE-2024-38264Sensitive Data Storage in Improperly Locked Memory in Microsoft Windows 11 Version 22h2

Severity
5.9MEDIUMNVD
EPSS
0.2%
top 55.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12

Description

Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages17 packages

NVDmicrosoft/windows< 10.0.25398.1251+1
NVDmicrosoft/windows_11_22h2< 10.0.22621.4460
NVDmicrosoft/windows_11_23h2< 10.0.22631.4460
NVDmicrosoft/windows_11_24h2< 10.0.26100.2314
CVEListV5microsoft/windows_server_202510.0.26100.010.0.26100.2314

Patches

🔴Vulnerability Details

1
GHSA
GHSA-f2vc-g638-2wm6: Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability2024-11-12

📋Vendor Advisories

1
Microsoft
Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability2024-11-12

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 89 flaws2024-11-12
CVE-2024-38264 — Microsoft vulnerability | cvebase