CVE-2024-38129

CVSS 3.1 Score 6.6 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Oct 22, 2024
CWE ID 285

Summary

CVE-2024-38129 represents a newly disclosed Windows Kerberos Elevation of Privilege vulnerability. An attacker who successfully exploits this issue can elevate their user privileges, potentially gaining administrative access to a system. This vulnerability impacts the Kerberos authentication protocol, which is used to secure communications between computers on a Windows network. Exploitation could occur through specially crafted messages that are sent to a target system. Mitigations include applying Microsoft's security updates as soon as they become available and implementing multi-factor authentication where possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft