CVE-2024-57972

The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic) through 10.0.22621.1244 allows remote attackers to cause a Denial of Service (resource consumption and device unusability) by sending many requests through the Device Portal framework.
Configurations

No configuration.

History

07 Mar 2025, 18:15

Type Values Removed Values Added
Summary
  • (es) El controlador de solicitudes de API de emparejamiento en Microsoft HoloLens 1 (Windows Holographic) hasta 10.0.17763.3046 y HoloLens 2 (Windows Holographic) hasta 10.0.22621.1244 permite a atacantes remotos provocar una denegación de servicio (consumo de recursos e inutilización del dispositivo) mediante el envío de muchas solicitudes a través del framework del Portal del dispositivo.
References () https://github.com/tania-silva/Hololens - () https://github.com/tania-silva/Hololens -

06 Mar 2025, 23:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-770
Summary (en) A vulnerability in the pairing request method in Microsoft HoloLens 1 and 2 - Windows Holographic 10.0.17763.3046 through 10.0.22621.1244 allows remote attackers to cause a Denial of Service via the Device Portal framework. (en) The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic) through 10.0.22621.1244 allows remote attackers to cause a Denial of Service (resource consumption and device unusability) by sending many requests through the Device Portal framework.

06 Mar 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-06 21:15

Updated : 2025-03-07 18:15


NVD link : CVE-2024-57972

Mitre link : CVE-2024-57972

CVE.ORG link : CVE-2024-57972


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling