CVE-2024-37979
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-37979 is a Windows Kernel Elevation of Privilege vulnerability that has been identified. Successful exploitation of this vulnerability allows an attacker to gain elevated system privileges, potentially allowing them to install unauthorized software, modify data, or access sensitive information. This is a serious security concern for Windows systems, as an elevated attacker can cause extensive damage to the affected system and the network it is connected to. Microsoft is currently working on a patch to address this issue, and it is recommended that users apply the patch as soon as it becomes available to mitigate the risk. In the meantime, users should practice good cybersecurity hygiene, including keeping their systems up-to-date with the latest security patches and using strong, unique passwords for all accounts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2022
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
- Microsoft Windows Server 2012 R2
Affected Vendors
- Microsoft