CVE-2024-43449

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 125

Summary

CVE-2024-43449 is a newly disclosed vulnerability affecting the Windows USB Video Class System Driver. This issue grants an attacker local elevation of privileges, meaning they can gain higher access levels within the operating system. An attacker could exploit this vulnerability by tricking a user into connecting a malicious USB device, leading to potential code execution and system compromise. This vulnerability poses a significant risk to Windows users, especially those who frequently connect external devices. It is important for affected systems to be patched as soon as possible to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows
  • Microsoft Windows 11
  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft