CVE-2024-6769

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Nov 21, 2024
CWE ID 426

Summary

CVE-2024-6769 is a newly disclosed vulnerability affecting Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022. The issue arises when a malicious actor leverages drive remapping in conjunction with a poisoned activation cache to carry out a DLL hijacking attack. This enables the attacker to elevate privileges from a medium integrity process to a high integrity process, bypassing the User Account Control (UAC) prompt. This vulnerability poses a serious threat to the security of these Microsoft operating systems and requires immediate attention and mitigation efforts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share