CVE-2024-38029
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 8, 2024
Updated: Oct 16, 2024
CWE ID 73
Summary
CVE-2024-38029 is a newly disclosed vulnerability affecting Microsoft OpenSSH for Windows. This issue permits an unauthenticated attacker to execute arbitrary code on targeted systems through a crafted SSH packet. Successful exploitation could lead to a complete system compromise, allowing the attacker to install programs, view, modify, or delete data. Organizations using Microsoft OpenSSH for Windows are advised to apply the forthcoming patch as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2022
Affected Vendors
- Microsoft