CVE detail
CVE-2024-38030
Windows Themes Spoofing Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
Yet another vulnerability has popped up in the way Windows handles the Themes that employees download in hopes of getting a snazzier desktop. But an expert says the impact of the hole could be blunted simply by blocking a port. The issue arose this week with a report from researchers at Acros Security of Slovenia, who […]
newswww.csoonline.comOct 31, 2024, 5:49 PMDespite two patching attempts, a security issue that may allow attackers to compromise Windows user’s NTLM (authentication) credentials via a malicious Windows themes file still affects Microsoft’s operating system, 0patch researchers have discovered. The path to discovery The story starts with CVE-2024-21320, a Windows Themes spoofing vulnerability that was reported by Akamai security researcher Tomer Peled and fixed by Microsoft in January 2024. The vulnerability could be triggered by a .theme file that specified a … More →
newswww.helpnetsecurity.comOct 29, 2024, 10:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-38017CVSS 5.5 · Medium
Microsoft Message Queuing Information Disclosure Vulnerability
- CVE-2024-30081CVSS 7.1 · High
Windows NTLM Spoofing Vulnerability
- CVE-2024-21320CVSS 6.5 · Medium
Windows Themes Spoofing Vulnerability
- CVE-2025-59214CVSS 6.5 · Medium
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-59211CVSS 5.5 · Medium
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
- CVE-2025-59209CVSS 5.5 · Medium
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.