CVE-2024-49046

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 367

Summary

CVE-2024-49046 is a newly disclosed Windows vulnerability affecting the Win32 Kernel Subsystem. This elevation of privilege vulnerability allows an attacker to potentially gain higher system privileges, increasing the risk of data theft or unauthorized system access. Specific details about the exploitation methods or required conditions are not currently available. Microsoft is encouraged to release a patch as soon as possible to mitigate potential threats. Users are advised to practice caution and keep their systems up to date with the latest security patches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows
  • Microsoft Windows 11
  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft