PT-2024-27910 · Unknown · Quick Share
Published
2024-04-17
·
Updated
2025-04-07
·
CVE-2024-38271
CVSS v4.0
5.9
Medium
| Vector | AV:A/AC:H/AT:P/PR:L/UI:A/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Quick Share versions prior to 1.0.1724.0
Description
There exists an issue in Quick Share/Nearby, where an attacker can force a victim to stay connected to a temporary hotspot created for the sharing. As part of the sequence of packets in a Quick Share connection over Bluetooth, the attacker forces the victim to connect to the attacker’s WiFi network and then sends an OfflineFrame that crashes Quick Share. This makes the WiFi connection to the attacker’s network last, instead of returning to the old network when the Quick Share session completes, allowing the attacker to be a Man-in-the-Middle (MiTM).
Recommendations
For versions prior to 1.0.1724.0, upgrade to version 1.0.1724.0 or above to resolve the issue. As a temporary workaround, consider disabling the Quick Share feature until a patch is available. Restrict access to unknown WiFi networks to minimize the risk of exploitation. Avoid using Quick Share over Bluetooth in public or untrusted environments until the issue is resolved.
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quick Share