CVE-2024-43500

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Oct 17, 2024
CWE ID 126

Summary

CVE-2024-43500 is a newly disclosed vulnerability affecting Microsoft's Resilient File System (ReFS). This issue permits an attacker to gain unauthorized access to sensitive file system information through a specially crafted sequence of commands. An attacker could exploit this vulnerability to obtain details about the file system structure, including file names, sizes, and locations. While no proof of exploitation has been reported yet, system administrators are advised to apply the forthcoming Microsoft patch to mitigate the risk. Failure to address this vulnerability could lead to data leakage or other potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 11 22h2
  • Microsoft Windows 11 23h2
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft