CVE-2024-38089 is a critical Elevation of Privilege vulnerability affecting Microsoft Defender for IoT. With a CVSS score of 9.9, it allows a low-privileged attacker to gain full control over the system remotely without user interaction. While there is no public exploit code or active exploitation reported, its high severity and potential for complete compromise warrant immediate patching. Community discussion and media coverage indicate awareness, but no widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 24.1.4CPE matchmatch criteria | cpe:2.3:a:microsoft:defender_for_iot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.