7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7 High
AI Score
Confidence
High
0.0005 Low
EPSS
Percentile
17.1%
The MsQuic server will continue to leak memory until no more is available, resulting in a denial of service.
The following patch was made:
Beyond upgrading to the patched versions, there is no other workaround.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190
CPE | Name | Operator | Version |
---|---|---|---|
microsoft.native.quic.msquic.schannel | eq | 1.8.0 | |
microsoft.native.quic.msquic.openssl | eq | 1.8.0 |
github.com/microsoft/msquic
github.com/microsoft/msquic/commit/5d070d661c45979946615289e92bb6b822efe9e9
github.com/microsoft/msquic/commit/933f7b79949bc588945672396d70b661143bb8f0
github.com/microsoft/msquic/security/advisories/GHSA-2x7m-gf85-3745
msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190
7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7 High
AI Score
Confidence
High
0.0005 Low
EPSS
Percentile
17.1%