CVE-2024-43626

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 122

Summary

CVE-2024-43626 is a newly disclosed vulnerability affecting the Windows Telephony Service. This elevation of privilege issue allows an attacker to gain higher system access by exploiting a vulnerability in the service. Successful exploitation could result in the attacker having the ability to install programs, modify data, or create new accounts with administrator privileges. This vulnerability poses a significant risk to Windows systems and requires immediate attention from system administrators to apply available patches or mitigations to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows
  • Microsoft Windows 11
  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft