CVE-2024-43535

CVSS 3.1 Score 7 of 10 (high)

Details

Published Oct 8, 2024
Updated: Oct 16, 2024
CWE ID 416

Summary

CVE-2024-43535 is a newly disclosed Windows Kernel-Mode driver vulnerability that allows an attacker to elevate their privileges. By exploiting this vulnerability, an attacker can gain control over a system, potentially leading to the installation of malware or unauthorized access to sensitive data. The exact cause of the vulnerability is not yet clear, but Microsoft is encouraging users to apply patches as soon as they become available to mitigate the risk. This type of vulnerability is particularly dangerous as it can be exploited locally, meaning an attacker does not need to have network access to target a system. Organizations and individuals are urged to prioritize the installation of updates to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share