Microsoft fixed a security flaw that could have let hackers install malware via Wi-Fi

Microsoft Security - Editorial Only
(Image credit: Alberto Garcia Guillen / Shutterstock)

This month’s Patch Tuesday fixed an important vulnerability in the Windows Wi-Fi driver which allowed threat actors to install malware via the wireless internet connectivity protocol.

The vulnerability is described as an improper input validation flaw that can result in remote code execution (RCE). It is tracked as CVE-2024-30078, and carries a severity score of 8.8. Microsoft labeled it as “important”. 

The company further explained how the bug could be abused in low-complexity attacks in which hackers do not need prior access. All they need to do is be within the vulnerable device’s Wi-Fi range so that they can send a custom-tailored network packet. Nothing is required on the victim’s end, as well, making this vulnerability particularly dangerous, especially for people who like to work from public spaces such as libraries, coffee shops, airports, and similar.

Almost 50 fixes

All common versions of the Windows OS are vulnerable, including both Windows 10, Windows 11, and Windows Server 2008 and newer, but while Microsoft said there is no evidence of the bug being abused in the wild, and that the exploitation is “unlikely”, shining a spotlight like this usually draws some attention from the criminals. 

Therefore, applying the latest Patch Tuesday cumulative update is always important.

Besides the improper input validation flaw, Microsoft fixed another 48 bugs in Windows and different Windows components, Office and Office components, Azure Dynamic Business Central, and Visual Studio, Tom’s Hardware reported. Among them is a “critical”-rated vulnerability in Microsoft Message Queuing that allowed threat actors to run malware with elevated privileges as unauthenticated users. 

Every second Tuesday in a month, Microsoft releases a batch of updates for Windows and other products, with a major focus on security and stability. This batch is dubbed Patch Tuesday, and is arguably the most important update for Windows. Every now and then, Microsoft also releases urgent fixes for high severity vulnerabilities that are known to be exploited in the wild.

Via Tom's Hardware

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Representational image of a cybercriminal
Microsoft just patched a host of worrying security issues, so update now
A hacker wearing a hoodie sitting at a computer, his face hidden.
Microsoft patches three worrying security flaws in its latest critical update, so update now
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Digital image of a lock.
Fortinet flags some worrying security bugs coming back from the dead
Representational image of a cybercriminal
Microsoft discovers five potentially damaging attacks against its own software
Outlook
Dangerous Microsoft Outlook flaw could let hackers send out malware via email
Latest in Security
3d rendering of a submarine power cable on the seabed
Subsea internet cables can now ‘listen’ for sabotage using irregular pulses of light
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Latest in News
3d rendering of a submarine power cable on the seabed
Subsea internet cables can now ‘listen’ for sabotage using irregular pulses of light
Google Pixel 9 front and back
The Google Pixel 9a has gone up for sale and it’s not even out yet
Panos Panay and Alexa Plus
Amazon's Panos Panay teases future Alexa+ devices from speakers to possible wearables
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Samsung Galaxy Z Fold 6
New rumors predict a foldable iPhone will launch next year – and cost almost twice as much as the iPhone 16 Pro Max
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away