Integer underflow in Microsoft Windows and Windows Server - CVE-2024-49103
Published: December 10, 2024
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to integer underflow in Windows Wireless Wide Area Network Service (WwanSvc). An authenticated attacker with physical access can send a specially crafted request to the affected application, trigger integer underflow and gain unauthorized access to sensitive information on the system.
Affected software
Windows Server
How to mitigate CVE-2024-49103
Windows Server - addressed in versions 2016 10.0.14393.7606, 2022 23H2 10.0.25398.1308, 2025 10.0.26100.2528, 2025 10.0.26100.2605