CVE-2024-38161

CVSS v3 Score
6.8
Medium

Vulnerability Description

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

CVSS:6.8(Medium)

User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and data leakage.

CVSS:6.8(Medium)

The RNDIS USB device class includes a buffer overflow vulnerability. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-...

CVSS:6.8(Medium)

Windows Boot Manager Security Feature Bypass Vulnerability