CVE-2024-43621

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 15, 2024
CWE ID 122

Summary

CVE-2024-43621 is a newly disclosed vulnerability affecting the Windows Telephony Service. This issue allows an attacker to execute remote code on vulnerable systems through a specially crafted message. Successful exploitation could result in significant security risks, including data theft, system compromise, or unauthorized access. The vulnerability is particularly concerning for organizations with large telecommunications infrastructures, as it could be exploited to gain access to sensitive information or disrupt critical services. Microsoft is aware of the issue and is currently working on a patch to address the problem. Users are strongly encouraged to apply updates as soon as they become available to minimize their risk of exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows
  • Microsoft Windows 11
  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft