CVE-2024-21435

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 12, 2024
Updated: Dec 27, 2024
CWE ID 426

Summary

CVE-2024-21435 is a newly disclosed vulnerability affecting Microsoft Windows systems. This issue involves a Remote Code Execution (RCE) vulnerability within the OLE (Object Linking and Embedding) component. An attacker can exploit this flaw by sending specially crafted data to a victim's system, resulting in arbitrary code execution. Successful exploitation could lead to serious consequences, including unauthorized system access, data theft, or further malware infection. Users are advised to install the upcoming Microsoft security patch as soon as it becomes available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 11 22h2
  • Microsoft Windows 11 23h2

Affected Vendors

  • Microsoft