CVE-2024-43620

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 15, 2024
CWE ID 122

Summary

CVE-2024-43620 is a newly disclosed vulnerability affecting the Windows Telephony Service. This issue permits an attacker to execute arbitrary code remotely by sending specially crafted RTP packets to a targeted system. Successful exploitation could lead to significant security implications, including data theft, unauthorized system access, or even complete system takeover. Users are advised to install the latest Microsoft security updates as soon as possible to mitigate this risk. Failure to address this vulnerability could result in severe consequences for organizations and individuals relying on the affected Windows systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows
  • Microsoft Windows 11
  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft