Use of uninitialized resource in Microsoft Windows and Windows Server - CVE-2024-38257
Published: September 10, 2024 / Updated: September 12, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to usage of uninitialized resources in Microsoft AllJoyn API. A remote attacker can pass specially crafted data to the application, trigger uninitialized usage of resources and gain access to sensitive information.
Affected software
Windows Server
How to mitigate CVE-2024-38257
Windows Server - addressed in versions 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700