CVE-2024-43552

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Oct 8, 2024
Updated: Oct 17, 2024
CWE ID 416

Summary

CVE-2024-43552 is a newly disclosed remote code execution vulnerability affecting Windows Shell. This issue allows an attacker to execute arbitrary code on a targeted system by manipulating specially crafted file name strings. Successful exploitation of this vulnerability could lead to the installation of malware, unauthorized system access, or other malicious activities. Users are strongly encouraged to apply the forthcoming Microsoft patch as soon as it becomes available to mitigate this risk. Until then, it is recommended to exercise caution when handling unfamiliar file transfers or downloads to minimize the potential of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 11 22h2
  • Microsoft Windows 11 23h2
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft