Out-of-bounds Read (CWE-125)
Windows Layer-2 Bridge Network Driver is vulnerable to a Denial of Service attack. This vulnerability is classified as an Out-of-bounds Read (CWE-125) issue. The attack vector is from an adjacent network, requires low attack complexity, and does not need user interaction or privileges.
This vulnerability could allow an attacker on an adjacent network to cause a Denial of Service condition, potentially disrupting the availability of the affected Windows system. The attack has a high impact on system availability but does not affect confidentiality or integrity of data.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available. Microsoft released an update to address this vulnerability on July 9, 2024.
Apply the security update provided by Microsoft as soon as possible. Prioritize patching based on the CVSS base score of 6.5 (Medium severity). In the interim, consider implementing network segmentation to limit access from adjacent networks and monitor for unusual network activity targeting the Layer-2 Bridge Network Driver.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Detection for the vulnerability has been added to Qualys (92149)
A CVSS base score of 6.5 has been assigned.
NVD published the first details for CVE-2024-38102
Feedly found the first article mentioning CVE-2024-38102. See article
Feedly estimated the CVSS score as MEDIUM
This CVE started to trend in security discussions
EPSS Score was set to: 0.04% (Percentile: 13%)
This CVE stopped trending in security discussions