CVE-2024-43517

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 8, 2024
Updated: Oct 17, 2024
CWE ID 122

Summary

CVE-2024-43517 is a newly disclosed Microsoft ActiveX Data Objects vulnerability that allows an attacker to execute arbitrary code remotely. An attacker can exploit this vulnerability by convincing a user to open a specially crafted file or visit a malicious website. Once exploited, the vulnerability can lead to the execution of malicious code on the affected system, potentially resulting in data theft, unauthorized access, or other malicious activities. Users are strongly encouraged to install the available Microsoft patches as soon as possible to mitigate this risk. Microsoft has stated that they are aware of active exploitation of this vulnerability in the wild.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share