Important CVSS 8.8 EPSS 0.05158 🔬 Patch diffed 2024-06 archive

Executive Summary

None

Overview

8.8
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Remote Code Execution
Released Jun 11 2024
Last Updated Jun 11 2024
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.05158 — 0.91692 percentile
NVD CVSS 8.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Adjacent_network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 7.7

EPSS Score

0.05158
probability of exploitation in the next 30 days
0.91692 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

28 affected products
Product KB Article Severity Impact Restart Required
Windows 10 for 32-bit Systems 5039225 (Security Update) Important Remote Code Execution Yes
Windows 10 for x64-based Systems 5039225 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1607 for 32-bit Systems 5039214 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1607 for x64-based Systems 5039214 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1809 for 32-bit Systems 5039217 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1809 for ARM64-based Systems 5039217 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1809 for x64-based Systems 5039217 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 21H2 for 32-bit Systems 5039211 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 21H2 for ARM64-based Systems 5039211 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 21H2 for x64-based Systems 5039211 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 22H2 for 32-bit Systems 5039211 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 22H2 for ARM64-based Systems 5039211 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 22H2 for x64-based Systems 5039211 (Security Update) Important Remote Code Execution Yes
Windows 11 version 21H2 for ARM64-based Systems 5039213 (Security Update) Important Remote Code Execution Yes
Windows 11 version 21H2 for x64-based Systems 5039213 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 22H2 for ARM64-based Systems 5039212 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 22H2 for x64-based Systems 5039212 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 23H2 for ARM64-based Systems 5039212 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 23H2 for x64-based Systems 5039212 (Security Update) Important Remote Code Execution Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 5039245 (Monthly Rollup) 5039266 (Security Only) Important Remote Code Execution 5037800 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22720 Yes 5039245 5039266 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5039245 (Monthly Rollup) 5039266 (Security Only) Important Remote Code Execution 5037800 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22720 Yes 5039245 5039266 Windows Server 2008 for x64-based Systems Service Pack 2 5039245 (Monthly Rollup) 5039266 (Security Only) Important Remote Code Execution 5037800 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22720 Yes 5039245 5039266 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5039245 (Monthly Rollup) 5039266 (Security Only) Important Remote Code Execution 5037800 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22720 Yes 5039245 5039266 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5039289 (Monthly Rollup) 5039274 (Security Only) Important Remote Code Execution 5037780 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27170 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5039289 (Monthly Rollup) 5039274 (Security Only) Important Remote Code Execution 5037780 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27170 Yes None Windows Server 2012 5039260 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2012 (Server Core installation) 5039260 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2012 R2 5039294 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2012 R2 (Server Core installation) 5039294 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2016 5039214 (Security Update) Important Remote Code Execution Yes
Windows Server 2016 (Server Core installation) 5039214 (Security Update) Important Remote Code Execution Yes
Windows Server 2019 5039217 (Security Update) Important Remote Code Execution Yes
Windows Server 2019 (Server Core installation) 5039217 (Security Update) Important Remote Code Execution Yes
Windows Server 2022 5039227 (Security Update) 5039330 (Security Hotpatch Update) Important Remote Code Execution 5037782 5037848 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.2527 10.0.20348.2522 Yes 5039227 Windows Server 2022 (Server Core installation) 5039227 (Security Update) 5039330 (Security Hotpatch Update) Important Remote Code Execution 5037782 5037848 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.2527 10.0.20348.2522 Yes 5039227 Windows Server 2022, 23H2 Edition (Server Core installation) 5039236 (Security Update) Important Remote Code Execution Yes

Patches

9 patches
Article Type Restart
5039225 Security Update Yes
5039214 Security Update Yes
5039217 Security Update Yes
5039211 Security Update Yes
5039213 Security Update Yes
5039212 Security Update Yes
5039260 Monthly Rollup Yes
5039294 Monthly Rollup Yes
5039236 Security Update Yes

Patch Diff

ghidriff · nwifi.sys (KB5039212)

Unauthenticated network-adjacent (over-the-air) OOB read/write (CWE-20) in the Native Wi-Fi driver nwifi.sys. On the receive path (Pt6Receive -> ExtSTARecvInitializeMSDUFromNBL -> ExtSTAReceivePacket -> ExtSTAReceiveDataPacket), Dot11Translate80211ToEthernetNdisPacket translates 802.11 frames to Ethernet in place. It validates the 8-byte LLC/SNAP header length, but when LLC type == 0x8100 (802.1Q VLAN) the extra 4-byte 802.1Q header follows and the pre-patch code did NOT verify those 4 bytes are present before reading them and deriving the Ethernet-header write offset - so a frame claiming VLAN with no VLAN payload reads the VLAN header OOB and (case 4: type 0x8100 && vlanid>=0x600, v17=LLC_off-0xE+4+8) writes the Ethernet header past the MDL buffer. Reachable from any device on the same Wi-Fi network (rogue AP / open net), no auth. IN-HOUSE ghidriff of nwifi.sys 10.0.22621.3527 -> .3733 (Jun 11 2024, the exact Crowdfense versions) confirms the fix: the 0x8100 branch adds `if (available < data_length + 0xc) goto bail` before reading the VLAN header, ensuring the extra 4 bytes fit. Length check reads unconditional (the Feature_1281542463 flag in the same build gates unrelated selective-translation work). Credit: aleksandr.k & voidsec (Crowdfense).

Pre-patch version 10.0.22621.3527 Download
Post-patch version 10.0.22621.3733 Download
Function Address Change Note
Dot11Translate80211ToEthernetNdisPacket code change code (802.1Q VLAN length check added) Pre: when LLC type == 0x8100 it read the 4-byte 802.1Q header and computed the Ethernet-header offset (case 4: LLC_off-0xE+4+8) without checking the 4 bytes were present -> OOB read then OOB write past the MDL buffer. Post: in the `if (uVar13 == 0x81)` (0x8100) branch adds `if (... available (lVar5+0x28) < *(uint*)(param_2+0xc) + 0xc) goto LAB_0` before reading the VLAN header, so the extra 4 bytes (0xC = 8 LLC + 4 VLAN) must fit.
Dot11CheckSelectiveTranslationTable code change code (co-changed selective-translation, Feature_1281542463) Also modified in this build; associated with the new Feature_1281542463 selective-translation work rather than the VLAN bounds fix.
View full diff report View RCA report

Attack Path

An 802.11 frame claiming a VLAN header it doesn't carry makes nwifi read/write past the packet buffer while building the Ethernet header

Attack path for CVE-2024-30078 An 802.11 frame claiming a VLAN header it doesn't carry makes nwifi read/write past the packet buffer while building the Ethernet header 01 — ENTRY Unauthenticated attacker on the same Wi-Fi network sends an 802.11 data frame nwifi.sys (Native Wi-Fi NDIS filter) receives frames via Pt6Receive from any associated device - e.g. a rogue AP the target connects to, or an open network. No authentication; network-adjacent RCE. 02 — CONTROLLED INPUT Frame sets LLC/SNAP type 0x8100 (802.1Q VLAN) but omits the 4-byte VLAN payload The receive path converts the NBL to an MSDU and calls Dot11Translate80211ToEthernetNdisPacket to translate 802.11 -> Ethernet in place. 03 — PATH The translator validates the 8-byte LLC header, then reads the VLAN header and derives the Ethernet write offset For LLC type 0x8100 it reads the following 802.1Q header (tpid/vlanid) and picks an Ethernet-header offset based on it (case 4: LLC_off-0xE+4+8). 04 — MISSING CHECK No check that the extra 4 VLAN bytes are present Pre-patch only the 8-byte LLC length is validated; the 4-byte 802.1Q header is read without a bounds check, so a VLAN-claiming frame with no VLAN bytes reads out of bounds and the Ethernet-header write lands past the MDL buffer (CWE-20 -> OOB read/write). 05 — PRIMITIVE Kernel out-of-bounds read/write on the Wi-Fi receive buffer -> RCE (constrained) In case 4 the Ethernet header is written past the 0x7800 adapter buffer. Practical impact is constrained (adjacent-packet corruption, no paired info-leak), but it is a genuine OOB write. The Jun 2024 fix adds `available < data_length + 0xc -> bail` in the 0x8100 branch.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Known Exploits

Acknowledgments

Wei in Kunlun Lab with Cyber KunLun