CVE-2024-43508

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Oct 17, 2024
CWE ID 125

Summary

CVE-2024-43508 is a newly disclosed information disclosure vulnerability affecting the Windows Graphics Component. Maliciously crafted graphics files can trigger the vulnerability, leading to the exposure of sensitive system information. Successful exploitation could potentially allow an attacker to gain knowledge about the operating system and its configurations, increasing the risk of further attacks. Microsoft is urging users to install the latest Windows updates to mitigate this vulnerability. Attackers can leverage this information to tailor their attacks, potentially leading to more effective and targeted cyber-assaults. Organizations are advised to implement network segmentation and access control policies to minimize the impact in case of a successful attack.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 11 22h2
  • Microsoft Windows 11 23h2
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft