Skip to main content
Vulnerability Database/CVE-2024-20690

CVE-2024-20690: Windows Nearby Sharing Spoofing Vulnerability

CVE-2024-20690 is a spoofing vulnerability in Windows 10 1809 Nearby Sharing that enables attackers to manipulate file sharing operations and deceive users. This article covers technical details, affected systems, and steps to secure your environment.

Published:

CVE-2024-20690 Overview

CVE-2024-20690 is a spoofing vulnerability affecting the Windows Nearby Sharing feature across multiple supported versions of Windows 10 and Windows 11. Microsoft published the advisory on January 9, 2024, addressing a flaw that allows a network-adjacent attacker to trick a user into accepting or interacting with a spoofed shared resource. Exploitation requires user interaction but no authentication. The vulnerability maps to [CWE-310] (Cryptographic Issues), reflecting weaknesses in the trust or verification model used by Nearby Sharing.

Critical Impact

A successful attacker can spoof a trusted sharing source over Nearby Sharing, leading to integrity compromise of files or content delivered to the victim's device.

Affected Products

  • Microsoft Windows 10 (versions 1809, 21H2, 22H2)
  • Microsoft Windows 11 (versions 21H2, 22H2, 23H2) on x64 and ARM64
  • Systems with Nearby Sharing enabled

Discovery Timeline

  • 2024-01-09 - CVE-2024-20690 published to NVD and addressed by Microsoft security update
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-20690

Vulnerability Analysis

Windows Nearby Sharing allows users to share files, links, and content between nearby devices using a combination of Bluetooth and Wi-Fi. The vulnerability lets an attacker present a spoofed identity or content source to a victim during a Nearby Sharing exchange. Because the underlying trust check does not sufficiently validate the sending peer, a victim can be misled into accepting content believed to originate from a trusted device.

The advisory categorizes the weakness under [CWE-310], pointing to deficiencies in cryptographic verification or trust attestation rather than a memory-safety issue. The attack does not grant code execution directly. It undermines the integrity assurance that Nearby Sharing provides, enabling downstream social engineering or malicious file delivery.

Root Cause

The root cause lies in insufficient validation of the identity or provenance of a sharing peer within the Nearby Sharing protocol. An attacker within transmission range or on the same network segment can craft transfer metadata that impersonates a legitimate device. The victim's client presents the attacker-controlled information as trustworthy, removing an important integrity check from the transfer workflow.

Attack Vector

Exploitation proceeds over the network and requires the victim to interact with the incoming share prompt. The attacker initiates a Nearby Sharing session that appears to originate from a legitimate or familiar sender. When the user accepts the share, the spoofed content is delivered with an implied level of trust. No prior authentication or elevated privilege is required on the target host.

No public proof-of-concept, exploit tooling, or CISA KEV listing exists for this issue at the time of publication. Refer to the Microsoft Security Response Center advisory for the authoritative technical description.

Detection Methods for CVE-2024-20690

Indicators of Compromise

  • Unexpected Nearby Sharing prompts referencing unfamiliar device names within Bluetooth or Wi-Fi range
  • Files landing in the %USERPROFILE%\Downloads directory with Nearby Sharing origin metadata but no corresponding user-initiated transfer
  • Bluetooth pairing or Wi-Fi Direct connection events preceding unexplained file drops

Detection Strategies

  • Correlate Windows event logs for BluetoothUserService and Nearby Sharing activity against user-reported transfers
  • Monitor endpoint telemetry for new executables or scripts written by the ShareHost.exe process
  • Baseline expected Nearby Sharing peer device identifiers in managed environments and flag deviations

Monitoring Recommendations

  • Enable file write auditing on user profile directories to capture Nearby Sharing drops
  • Track Group Policy state for Nearby Sharing configuration changes across managed endpoints
  • Alert on receipt of executable file types (.exe, .msi, .lnk, .ps1) via Nearby Sharing on workstations that do not require this workflow

How to Mitigate CVE-2024-20690

Immediate Actions Required

  • Apply the January 2024 Microsoft security updates referenced in the MSRC advisory for CVE-2024-20690 to all affected Windows 10 and Windows 11 builds
  • Disable Nearby Sharing on endpoints that do not require it, especially in shared office space or public environments
  • Educate users to reject Nearby Sharing prompts from unrecognized device names

Patch Information

Microsoft addressed the vulnerability in the January 9, 2024 cumulative security updates for supported Windows 10 and Windows 11 releases. Consult the Microsoft Security Update Guide for the specific KB article that applies to each affected build and architecture.

Workarounds

  • Set Nearby Sharing to Off under Settings > System > Nearby sharing on hosts that cannot be patched immediately
  • Use Group Policy or Mobile Device Management to disable Nearby Sharing across the fleet
  • Restrict Bluetooth usage on sensitive endpoints through endpoint policy where operationally feasible
bash
# Configuration example: disable Nearby Sharing via registry
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\CDP" /v NearShareChannelUserAuthzPolicy /t REG_DWORD /d 0 /f
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\CDP" /v CdpSessionUserAuthzPolicy /t REG_DWORD /d 0 /f

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.