CVE-2024-43621
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-43621 is a newly disclosed vulnerability affecting the Windows Telephony Service. This issue allows an attacker to execute remote code on vulnerable systems through a specially crafted message. Successful exploitation could result in significant security risks, including data theft, system compromise, or unauthorized access. The vulnerability is particularly concerning for organizations with large telecommunications infrastructures, as it could be exploited to gain access to sensitive information or disrupt critical services. Microsoft is aware of the issue and is currently working on a patch to address the problem. Users are strongly encouraged to apply updates as soon as they become available to minimize their risk of exposure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows
- Microsoft Windows 11
- Microsoft Windows Server 2008
Affected Vendors
- Microsoft