Heap-based Buffer Overflow (CWE-122)
Windows IP Routing Management Snapin Remote Code Execution Vulnerability. This vulnerability allows remote code execution with a network-based attack vector. It requires user interaction but no privileges. The attack complexity is low, and it affects the confidentiality, integrity, and availability of the system, all with high impact.
If successfully exploited, this vulnerability could allow an attacker to execute arbitrary code on the target system with the same privileges as the user running the Windows IP Routing Management Snapin. Given the high impact on confidentiality, integrity, and availability, the attacker could potentially gain full control of the affected system, access sensitive information, modify or delete data, and disrupt system operations. The network-based attack vector means that the attacker could potentially exploit this vulnerability remotely, increasing its severity.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available. Microsoft has released an official fix for this vulnerability on August 13, 2024.
1. Apply the official patch released by Microsoft as soon as possible. 2. Implement the principle of least privilege, ensuring users only have the necessary permissions to perform their tasks. 3. Educate users about the risks of interacting with untrusted content, as user interaction is required for exploitation. 4. Implement network segmentation and firewall rules to limit exposure to potential attacks. 5. Regularly monitor and audit systems for any suspicious activities. 6. Keep all Windows systems and software up to date with the latest security patches.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Detection for the vulnerability has been added to Qualys (92160)
A CVSS base score of 8.8 has been assigned.
Feedly found the first article mentioning CVE-2024-38115. See article
Feedly estimated the CVSS score as HIGH
NVD published the first details for CVE-2024-38115
EPSS Score was set to: 0.15% (Percentile: 52.3%)