First published: Thu Mar 06 2025(Updated: )
The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic) through 10.0.22621.1244 allows remote attackers to cause a Denial of Service (resource consumption and device unusability) by sending many requests through the Device Portal framework.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft HoloLens 1 | <=10.0.17763.3046 | |
Microsoft HoloLens 2 | <=10.0.22621.1244 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-57972 has a severity rating that indicates it allows remote attackers to cause a Denial of Service.
CVE-2024-57972 affects Microsoft HoloLens 1 and 2, specifically versions up to 10.0.17763.3046 and 10.0.22621.1244 respectively.
To fix CVE-2024-57972, ensure that your Microsoft HoloLens device is updated to the latest security patches provided by Microsoft.
CVE-2024-57972 primarily allows Denial of Service, and does not directly enable data theft.
CVE-2024-57972 can be exploited remotely, so adequate security measures should be taken to mitigate the risk.