CVE-2024-43522

CVSS 3.1 Score 7 of 10 (high)

Details

Published Oct 8, 2024
Updated: Oct 17, 2024
CWE ID 122

Summary

CVE-2024-43522 is a newly disclosed Windows Local Security Authority (LSA) vulnerability. Hackers can exploit this elevation of privilege vulnerability to gain administrative control over a targeted system. The LSA is a critical security component in Windows that manages local and domain security policies, and this vulnerability could allow an attacker to bypass security restrictions. The exact technical details of the exploit are not yet publicly available, but affected users are advised to apply patches as soon as they become available to mitigate the risk. This vulnerability underscores the importance of keeping software up-to-date to protect against potential cyber threats.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 11 22h2
  • Microsoft Windows 11 23h2

Affected Vendors

  • Microsoft