CVE-2024-43644

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 125

Summary

CVE-2024-43644 is a newly disclosed vulnerability affecting Windows' Client-Side Caching feature. Attackers can exploit this elevation of privilege vulnerability by tricking a user into opening a specially crafted webpage. Successful exploitation grants the attacker system-level access, enabling them to install programs, modify data, or create new accounts with full user rights. This vulnerability poses a significant risk to organizations and individuals using affected Windows systems, and it is recommended to patch as soon as possible to mitigate potential threats.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows
  • Microsoft Windows 11
  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft