mdlbear: blue fractal bear with text "since 2002" (Default)
[personal profile] mdlbear

A tip of the hat to solarbird's post titled: "uh if you have windows and wifi this is VERY IMPORTANT" -- and it is. If you haven't updated Windows this week, DO IT NOW. This affects all currently-supported versions of Windows.

Let me present CVE-2024-30078 - Microsoft - Windows Wi-Fi Driver Remote Code Execution Vulnerability. The money quote is:

According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?

Exploiting this vulnerability requires an attacker to be within proximity of the target system to send and receive radio transmissions.

How could an attacker exploit the vulnerability?

An unauthenticated attacker could send a malicious networking packet to an adjacent system that is employing a Wi-Fi networking adapter, which could enable remote code execution.

It does not say whether the target machine (you) needs to be connected to the WiFi network -- because this is happening at the driver level, probably not. It affects Windows 11, Windows 10, and all versions of Windows Server back to 2008.

It also doesn't say whether earlier, unsupported versions of Windows are affected, but it's safe to assume that they probably are as well. So if you're running, say, Windows 7, there's never been a better time to upgrade to Linux.

More:

This account has disabled anonymous posting.
(will be screened if not validated)
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org

Most Popular Tags

Style Credit

Page generated 2025-06-13 12:57 am
Powered by Dreamwidth Studios