CVE-2024-43639

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 14, 2024
CWE ID 197

Summary

CVE-2024-43639 is a newly disclosed vulnerability affecting Windows Kerberos Domain Controller (KDC) Proxy. Hackers can exploit this remote code execution (RCE) flaw to gain unauthorized access to a targeted system. The vulnerability arises due to improper handling of certain protocol messages, allowing attackers to inject and execute malicious code. Successful exploitation could result in significant damage, including data theft, system compromise, and potential spread to other connected systems within a network. Microsoft has released a patch to address this issue, and it is recommended that all Windows servers be upgraded promptly to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows

Affected Vendors

  • Microsoft