CVE-2024-30078 — Windows Wi-Fi Driver Remote Code Execution Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5039225 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 for x64-based Systems | 5039225 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5039214 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5039214 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5039217 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 5039217 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5039217 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5039211 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5039211 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5039211 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5039211 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5039211 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5039211 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 version 21H2 for ARM64-based Systems | 5039213 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 version 21H2 for x64-based Systems | 5039213 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5039212 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5039212 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5039212 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5039212 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 5039245 (Monthly Rollup) 5039266 (Security Only) Important Remote Code Execution 5037800 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22720 Yes 5039245 5039266 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5039245 (Monthly Rollup) 5039266 (Security Only) Important Remote Code Execution 5037800 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22720 Yes 5039245 5039266 Windows Server 2008 for x64-based Systems Service Pack 2 5039245 (Monthly Rollup) 5039266 (Security Only) Important Remote Code Execution 5037800 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22720 Yes 5039245 5039266 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5039245 (Monthly Rollup) 5039266 (Security Only) Important Remote Code Execution 5037800 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22720 Yes 5039245 5039266 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5039289 (Monthly Rollup) 5039274 (Security Only) Important Remote Code Execution 5037780 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27170 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5039289 (Monthly Rollup) 5039274 (Security Only) Important Remote Code Execution 5037780 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27170 Yes None Windows Server 2012 | 5039260 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 (Server Core installation) | 5039260 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 R2 | 5039294 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5039294 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2016 | 5039214 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2016 (Server Core installation) | 5039214 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 | 5039217 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 (Server Core installation) | 5039217 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2022 5039227 (Security Update) 5039330 (Security Hotpatch Update) Important Remote Code Execution 5037782 5037848 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.2527 10.0.20348.2522 Yes 5039227 Windows Server 2022 (Server Core installation) 5039227 (Security Update) 5039330 (Security Hotpatch Update) Important Remote Code Execution 5037782 5037848 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.2527 10.0.20348.2522 Yes 5039227 Windows Server 2022, 23H2 Edition (Server Core installation) | 5039236 (Security Update) |
Important | Remote Code Execution | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5039225 |
Security Update | Yes |
5039214 |
Security Update | Yes |
5039217 |
Security Update | Yes |
5039211 |
Security Update | Yes |
5039213 |
Security Update | Yes |
5039212 |
Security Update | Yes |
5039260 |
Monthly Rollup | Yes |
5039294 |
Monthly Rollup | Yes |
5039236 |
Security Update | Yes |
Patch Diff
Unauthenticated network-adjacent (over-the-air) OOB read/write (CWE-20) in the Native Wi-Fi driver nwifi.sys. On the receive path (Pt6Receive -> ExtSTARecvInitializeMSDUFromNBL -> ExtSTAReceivePacket -> ExtSTAReceiveDataPacket), Dot11Translate80211ToEthernetNdisPacket translates 802.11 frames to Ethernet in place. It validates the 8-byte LLC/SNAP header length, but when LLC type == 0x8100 (802.1Q VLAN) the extra 4-byte 802.1Q header follows and the pre-patch code did NOT verify those 4 bytes are present before reading them and deriving the Ethernet-header write offset - so a frame claiming VLAN with no VLAN payload reads the VLAN header OOB and (case 4: type 0x8100 && vlanid>=0x600, v17=LLC_off-0xE+4+8) writes the Ethernet header past the MDL buffer. Reachable from any device on the same Wi-Fi network (rogue AP / open net), no auth. IN-HOUSE ghidriff of nwifi.sys 10.0.22621.3527 -> .3733 (Jun 11 2024, the exact Crowdfense versions) confirms the fix: the 0x8100 branch adds `if (available < data_length + 0xc) goto bail` before reading the VLAN header, ensuring the extra 4 bytes fit. Length check reads unconditional (the Feature_1281542463 flag in the same build gates unrelated selective-translation work). Credit: aleksandr.k & voidsec (Crowdfense).
| Function | Address | Change | Note |
|---|---|---|---|
Dot11Translate80211ToEthernetNdisPacket |
code change |
code (802.1Q VLAN length check added) | Pre: when LLC type == 0x8100 it read the 4-byte 802.1Q header and computed the Ethernet-header offset (case 4: LLC_off-0xE+4+8) without checking the 4 bytes were present -> OOB read then OOB write past the MDL buffer. Post: in the `if (uVar13 == 0x81)` (0x8100) branch adds `if (... available (lVar5+0x28) < *(uint*)(param_2+0xc) + 0xc) goto LAB_0` before reading the VLAN header, so the extra 4 bytes (0xC = 8 LLC + 4 VLAN) must fit. |
Dot11CheckSelectiveTranslationTable |
code change |
code (co-changed selective-translation, Feature_1281542463) | Also modified in this build; associated with the new Feature_1281542463 selective-translation work rather than the VLAN bounds fix. |
Attack Path
An 802.11 frame claiming a VLAN header it doesn't carry makes nwifi read/write past the packet buffer while building the Ethernet header
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Known Exploits
Acknowledgments
Wei in Kunlun Lab with Cyber KunLun