CVE-2024-30012 is a Remote Code Execution vulnerability in the Windows Mobile Broadband Driver affecting various versions of Windows 10, 11, and Server. With a CVSS score of 6.8 (Medium), it requires physical access to the target system (AV:P) but has low attack complexity (AC:L), potentially leading to high confidentiality, integrity, and availability impacts. There is currently no public exploit code available, it is not listed in CISA's KEV catalog, and community discussion and media coverage are minimal, indicating low current exploitation activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.5820CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:* | ||
< 10.0.19044.4412CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.4412CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22000.2960CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.22621.3593CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.