CVE-2024-38196

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Aug 13, 2024
Updated: Aug 15, 2024
CWE ID 20

Summary

CVE-2024-38198 is a newly disclosed vulnerability affecting the Windows Print Spooler service. This elevation of privilege issue allows an unauthenticated attacker to install and run programs with administrative privileges by leveraging a specially crafted print job. Successful exploitation could lead to significant compromise, including unauthorized access to sensitive information or system takeover. Users are strongly encouraged to apply the forthcoming Microsoft patch as soon as it becomes available to mitigate this risk. In the interim, implementing Printer Protection in Group Policy or disabling the Print Spooler service may offer some level of protection.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share