CVE-2024-45383
MEDIUMMicrosoft High Definition Audio Bus Driver 10.0.19041.3636 - DoS
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-45383. PoCs published by SpiralBL0CK.
AI-analyzed exploit summary This PoC demonstrates a vulnerability in Windows WMI (Windows Management Instrumentation) by leveraging the WmiOpenBlock, WmiQueryAllData, and WmiCloseBlock functions to interact with the WmiMonitorID_GUID. The code initializes a handle to the WMI block, which could be exploited for privilege escalation or information disclosure.
Description
A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests which leads to a local denial-of-service. An attacker can execute malicious script/application to trigger this vulnerability.
Exploits (1)
This PoC demonstrates a vulnerability in Windows WMI (Windows Management Instrumentation) by leveraging the WmiOpenBlock, WmiQueryAllData, and WmiCloseBlock functions to interact with the WmiMonitorID_GUID. The code initializes a handle to the WMI block, which could be exploited for privilege escalation or information disclosure.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H