CVE-2026-24288
vulnerability analysis and mitigation

Overview

CVE-2026-24288 is a heap-based buffer overflow vulnerability in the Windows Mobile Broadband component that allows an unauthorized attacker to execute arbitrary code via a physical attack. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects Windows 10 versions 21H2 (before build 10.0.19044.7058) and 22H2 (before build 10.0.19045.7058) across x86, x64, and ARM64 architectures. It carries a CVSS v3.1 base score of 6.8 (Medium), reflecting the physical access requirement (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) within the Windows Mobile Broadband driver stack. An attacker with physical access to a vulnerable device can trigger the overflow by interacting with the Mobile Broadband interface — for example, by connecting a specially crafted USB or hardware device — causing memory corruption that leads to arbitrary code execution. No user interaction is required beyond the physical access itself, and no privileges are needed on the target system (Microsoft MSRC).

Impact

Successful exploitation grants an attacker the ability to execute arbitrary code on the affected device, potentially resulting in complete system compromise including data theft, system manipulation, and service disruption. All three security pillars — confidentiality, integrity, and availability — are rated HIGH impact. Because the attack vector is physical, lateral movement to networked systems is a secondary risk contingent on the attacker gaining an initial foothold on the device (Microsoft MSRC).

Exploitation steps

  1. Physical Access: Obtain physical access to a Windows 10 21H2 or 22H2 device running a build prior to 10.0.19044.7058 or 10.0.19045.7058 respectively.
  2. Identify Target Component: Confirm the device has Windows Mobile Broadband functionality enabled (e.g., a built-in LTE/5G modem or a connected USB Mobile Broadband adapter).
  3. Trigger Buffer Overflow: Interact with the Mobile Broadband interface using a crafted device or input designed to overflow the heap buffer in the vulnerable driver, causing memory corruption.
  4. Achieve Code Execution: Leverage the memory corruption to redirect execution flow and run arbitrary code in the context of the vulnerable driver or system process, potentially gaining elevated privileges on the device (Microsoft MSRC).

Mitigation and workarounds

Microsoft released patches on March 10, 2026 as part of the March 2026 Patch Tuesday update cycle. Organizations should update affected systems to Windows 10 21H2 build 10.0.19044.7058 or later, and Windows 10 22H2 build 10.0.19045.7058 or later. As a compensating control, organizations should enforce strict physical access controls to limit unauthorized access to vulnerable devices, particularly for unattended or publicly accessible endpoints (Microsoft MSRC).

Community reactions

Coverage of CVE-2026-24288 appeared primarily in the context of the broader March 2026 Patch Tuesday roundups, with security outlets such as BleepingComputer, Rapid7, Zero Day Initiative, and Sophos covering the overall update release (Rapid7 Blog, ZDI Blog, Sophos Blog). The vulnerability did not attract significant individual attention given its physical-access-only attack vector and medium CVSS score. No notable researcher commentary specific to this CVE has been identified.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management