CVE-2024-49110 is an Elevation of Privilege vulnerability affecting the Windows Mobile Broadband Driver across various Windows 10, 11, and Server versions. With a CVSS score of 6.8 (Medium), this vulnerability allows an attacker with physical access to the device to achieve high impact on confidentiality, integrity, and availability. While it has a low EPSS score and is not listed in CISA KEV, indicating no active exploitation, it was mentioned in a BleepingComputer article regarding Microsoft's December 2024 Patch Tuesday. There is currently no public exploit code available on platforms like Metasploit or ExploitDB, and community discussion is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.6659CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.6659CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.5247CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.5247CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22621.4602CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.