Out-of-bounds Read (CWE-125)
Security Center Broker Information Disclosure Vulnerability. This vulnerability is classified as an out-of-bounds read issue (CWE-125). It affects various versions of Microsoft Windows, including Windows 10 and Windows 11.
An attacker who successfully exploits this vulnerability could gain access to sensitive information. The vulnerability has a high impact on confidentiality, but no impact on integrity or availability. The attack vector is local, requiring low privileges and no user interaction.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available. Microsoft has released updates to address this vulnerability.
Apply the latest security updates provided by Microsoft for the affected Windows versions. Specifically, update to versions newer than: - Windows 11 23H2: 10.0.22631.4037 - Windows 11 24H2: 10.0.26100.1457 - Windows 10 22H2: 10.0.19045.4780 - Windows 10 1809: 10.0.17763.6189 - Windows 11 21H2: 10.0.22000.3147 - Windows 11 22H2: 10.0.22621.4037 - Windows 10 21H2: 10.0.19044.4780 Implement the principle of least privilege to minimize the potential impact of local attacks.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Detection for the vulnerability has been added to Qualys (92160)
A CVSS base score of 5.5 has been assigned.
Feedly found the first article mentioning CVE-2024-38155. See article
NVD published the first details for CVE-2024-38155
Feedly estimated the CVSS score as MEDIUM
EPSS Score was set to: 0.05% (Percentile: 19%)