CVE-2024-38029

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 8, 2024
Updated: Oct 16, 2024
CWE ID 73

Summary

CVE-2024-38029 is a newly disclosed vulnerability affecting Microsoft OpenSSH for Windows. This issue permits an unauthenticated attacker to execute arbitrary code on targeted systems through a crafted SSH packet. Successful exploitation could lead to a complete system compromise, allowing the attacker to install programs, view, modify, or delete data. Organizations using Microsoft OpenSSH for Windows are advised to apply the forthcoming patch as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft