CVE-2024-38257
Microsoft AllJoyn API Information Disclosure Vulnerability
CVSS
7.5
High
EPSS
4.5%
p91
KEV
—
Exploit Today
27
0-100
Published: Sep 10, 2024 · Last modified: Aug 10, 2026 · CWE-908
4.5%EPSS · 30 days4.5%
2026-07-142026-08-10
Microsoft AllJoyn API Information Disclosure Vulnerability
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-703175.5 MED—
———Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.14hCVE-2026-687995.5 MED—
———Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.11hCVE-2026-627405.5 MED—
———Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.10hCVE-2026-627095.5 MED—
———Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.10hCVE-2026-591375.5 MED—
———Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.10hCVE-2026-591365.5 MED—
———Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.10h