cve/2024/CVE-2024-57972.md

19 lines
911 B
Markdown
Raw Normal View History

2025-09-29 16:08:36 +00:00
### [CVE-2024-57972](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57972)
2025-09-29 21:09:30 +02:00
![](https://img.shields.io/static/v1?label=Product&message=HoloLens&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=10%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-770%20Allocation%20of%20Resources%20Without%20Limits%20or%20Throttling&color=brightgreen)
2025-09-29 16:08:36 +00:00
### Description
The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic) through 10.0.22621.1244 allows remote attackers to cause a Denial of Service (resource consumption and device unusability) by sending many requests through the Device Portal framework.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/plzheheplztrying/cve_monitor
- https://github.com/tania-silva/CVE-2024-57972