Junglewise Threat Intelligence

CVE-2024-43572: Microsoft Windows Management Console Remote Code Execution Vulnerability

CVE-2024-43572 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2024-10-08

Technologies: Microsoft Windows, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server. Vendors: Microsoft.

Executive brief

Microsoft Windows Management Console contains a remote code execution vulnerability due to improper neutralization of input. An attacker can exploit this by convincing a user to open a malicious file, leading to code execution with the privileges of the user.

Affected products

  • Microsoft Windows Management Console
  • Microsoft Windows 10 up to (excluding) 10.0.10240.20796, 10.0.19044.5011, 10.0.19045.5011, 10.0.14393.7428, 10.0.17763.6414
  • Microsoft Windows 11 up to (excluding) 10.0.22631.4317, 10.0.22000.3260
  • Microsoft Windows Server 2008, 2012, 2016, 2019, 2022

Timeline

  • 2024-10-08: disclosed
  • 2024-10-08: patched
  • 2024-10-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-10-08: exploited: Reported as exploited in the wild at time of publication.

Related threats