#VU101432 Integer underflow in Windows and Windows Server - CVE-2024-49103
Published: December 10, 2024
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to integer underflow in Windows Wireless Wide Area Network Service (WwanSvc). An authenticated attacker with physical access can send a specially crafted request to the affected application, trigger integer underflow and gain unauthorized access to sensitive information on the system.