Exposure of Sensitive Information to an Unauthorized Actor (CWE-200)
Windows Themes Spoofing Vulnerability. This vulnerability allows an attacker to potentially access sensitive information. It affects various versions of Windows operating systems, including Windows 10, Windows 11, and Windows Server editions.
If exploited, this vulnerability could lead to unauthorized disclosure of sensitive information. The attack requires user interaction and can be initiated from a network, potentially allowing remote attackers to gain access to confidential data. The vulnerability has a high impact on confidentiality, but no direct impact on integrity or availability of the system. The CVSS base score is 6.5, indicating a medium severity level.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available. Microsoft has released updates to address this vulnerability across affected Windows versions. Users should update to the following versions or later: Windows 11 23H2: 10.0.22631.3880 Windows 10 1507: 10.0.10240.20710 Windows Server 2016: 10.0.14393.7159 Windows Server 2019: 10.0.17763.6054 Windows 11 21H2: 10.0.22000.3079 Windows 11 22H2: 10.0.22621.3880 Windows 10 21H2: 10.0.19044.4651 Windows 10 1809: 10.0.17763.6054 Windows Server 2022: 10.0.20348.2582 Windows 10 22H2: 10.0.19045.4651 Windows Server 2012 and Windows Server 2012 R2: Latest updates Windows 10 1607: 10.0.14393.7159
1. Apply the latest security updates provided by Microsoft for the affected Windows versions. 2. Implement the principle of least privilege to minimize the potential impact of the vulnerability. 3. Educate users about the risks of interacting with untrusted content from network sources. 4. Consider implementing additional network security measures to detect and prevent potential exploitation attempts. 5. Regularly monitor system logs for any suspicious activities related to information disclosure.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Detection for the vulnerability has been added to Qualys (92149)
A CVSS base score of 6.5 has been assigned.
NVD published the first details for CVE-2024-38030
Feedly found the first article mentioning CVE-2024-38030. See article
Feedly estimated the CVSS score as MEDIUM
EPSS Score was set to: 0.09% (Percentile: 37.4%)
This CVE started to trend in security discussions
This CVE stopped trending in security discussions