Microsoft recently confirmed the existence of vulnerability number CVE-2024-30078, a new Wi-Fi takeover attack that could allow unscrupulous individuals to remotely inject malware into users’ Windows computers. This vulnerability was not initially disclosed publicly. Now Microsoft has released a corresponding fix. Remember to install it in time.

Wi-Fi vulnerability in Windows could allow hackers to take over computers remotely
Let’s first understand CVE-2024-30078 This security vulnerability. It is a newly confirmed vulnerability in the Windows Wi-Fi driver that allows attackers to remotely execute arbitrary code on the target system. This means that the attacker can install malware or execute other malicious code on the device through Wi-Fi without the user’s knowledge. Microsoft confirmed the issue in a security update and also confirmed that the vulnerability does not require prior special permissions or prior access to be exploited. The vulnerability is contained in Windows’ universal Wi-Fi driver code, so it will affect all Windows 11 users.

Essentially, it is a zero-click attack because no user interaction is required to exploit the target computer. Malicious actors can use specially crafted packets to target specific computers, which can execute remote code on the target computer. The vulnerability, rated 8.8, requires the attacker to be connected to the same Wi-Fi environment as the target computer, but does not require any prior access. The vulnerability also exists on ARM Windows laptops.

If you haven’t updated Windows to the latest version yet, you should do so now. CVE stands for Common Vulnerabilities and Exposures and is a maintained list of vulnerabilities and exploits in computer systems. The vulnerability discovered this time may have been disclosed to Microsoft by an internal security team or a third party. It’s common for liability disclosures of this nature to tinker with and publish partial details before all the details are confirmed, giving the public time to update the device before the exact details are known.

Microsoft disclosed that they do not believe that the vulnerability has been exploited maliciously by anyone, but this is not an absolute guarantee. However, just knowing that a driver-level remote code execution vulnerability exists in Windows immediately paints a lucrative target for bad actors, and many online groups may now be trying to reverse engineer the vulnerability. It’s also possible that a threat actor unknown to Microsoft has exploited this vulnerability before, and Microsoft simply wasn’t aware of it.

While these types of vulnerabilities are very rare, they do happen and it’s important to protect yourself and not leave things to chance. In this case, the best way is to make sure your device is up to date. Take some time to double-check that your computer has automatic software updates enabled. While Windows Update is notoriously annoying and poorly timed, it does deliver important security patches on a regular basis.
Source: KOCPC Chinese