CVE-2024-43624

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 822

Summary

CVE-2024-43624 is a newly disclosed vulnerability affecting Windows Hyper-V's Shared Virtual Disk feature. This elevation of privilege issue allows unprivileged users to gain administrator-level access to the Hyper-V host system. By manipulating the authentication mechanism of the Shared Virtual Disk, an attacker can exploit this vulnerability and escalate their privileges, potentially leading to serious security implications. Microsoft has acknowledged the issue and is working on a patch to address it. In the meantime, it is recommended that affected organizations apply mitigations and restrict access to the Shared Virtual Disk functionality until a fix is available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows
  • Microsoft Windows 11

Affected Vendors

  • Microsoft