CVE-2024-45383

A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests which leads to a local denial-of-service. An attacker can execute malicious script/application to trigger this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:high_definition_audio_bus_driver:10.0.19041.3636:*:*:*:*:*:*:*

History

21 Nov 2024, 09:37

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2008 -

18 Sep 2024, 20:24

Type Values Removed Values Added
First Time Microsoft
Microsoft high Definition Audio Bus Driver
Summary
  • (es) Existe una vulnerabilidad de gestión incorrecta de solicitudes IRP en la interfaz HDAudBus_DMA de Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). Una aplicación especialmente manipulada puede emitir múltiples solicitudes IRP Complete, lo que genera una denegación de servicio local. Un atacante puede ejecutar una aplicación o un script malicioso para activar esta vulnerabilidad.
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2008 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2008 - Exploit, Third Party Advisory
CPE cpe:2.3:a:microsoft:high_definition_audio_bus_driver:10.0.19041.3636:*:*:*:*:*:*:*

12 Sep 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-12 19:15

Updated : 2024-11-21 09:37


NVD link : CVE-2024-45383

Mitre link : CVE-2024-45383

CVE.ORG link : CVE-2024-45383


JSON object : View

Products Affected

microsoft

  • high_definition_audio_bus_driver
CWE
CWE-664

Improper Control of a Resource Through its Lifetime