Integer underflow in Windows and Windows Server - CVE-2024-49103

 

Integer underflow in Windows and Windows Server - CVE-2024-49103

Published: December 10, 2024


Vulnerability identifier: #VU101432
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-49103
CWE-ID: CWE-191
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
Windows
Windows Server

Detailed vulnerability description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to integer underflow in Windows Wireless Wide Area Network Service (WwanSvc). An authenticated attacker with physical access can send a specially crafted request to the affected application, trigger integer underflow and gain unauthorized access to sensitive information on the system.


How to mitigate CVE-2024-49103

Install updates from vendor's website.

Sources