
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24288 is a heap-based buffer overflow vulnerability in the Windows Mobile Broadband component that allows an unauthorized attacker to execute arbitrary code via a physical attack. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects Windows 10 versions 21H2 (before build 10.0.19044.7058) and 22H2 (before build 10.0.19045.7058) across x86, x64, and ARM64 architectures. It carries a CVSS v3.1 base score of 6.8 (Medium), reflecting the physical access requirement (Microsoft MSRC).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) within the Windows Mobile Broadband driver stack. An attacker with physical access to a vulnerable device can trigger the overflow by interacting with the Mobile Broadband interface — for example, by connecting a specially crafted USB or hardware device — causing memory corruption that leads to arbitrary code execution. No user interaction is required beyond the physical access itself, and no privileges are needed on the target system (Microsoft MSRC).
Successful exploitation grants an attacker the ability to execute arbitrary code on the affected device, potentially resulting in complete system compromise including data theft, system manipulation, and service disruption. All three security pillars — confidentiality, integrity, and availability — are rated HIGH impact. Because the attack vector is physical, lateral movement to networked systems is a secondary risk contingent on the attacker gaining an initial foothold on the device (Microsoft MSRC).
Microsoft released patches on March 10, 2026 as part of the March 2026 Patch Tuesday update cycle. Organizations should update affected systems to Windows 10 21H2 build 10.0.19044.7058 or later, and Windows 10 22H2 build 10.0.19045.7058 or later. As a compensating control, organizations should enforce strict physical access controls to limit unauthorized access to vulnerable devices, particularly for unattended or publicly accessible endpoints (Microsoft MSRC).
Coverage of CVE-2026-24288 appeared primarily in the context of the broader March 2026 Patch Tuesday roundups, with security outlets such as BleepingComputer, Rapid7, Zero Day Initiative, and Sophos covering the overall update release (Rapid7 Blog, ZDI Blog, Sophos Blog). The vulnerability did not attract significant individual attention given its physical-access-only attack vector and medium CVSS score. No notable researcher commentary specific to this CVE has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."