CVE-2024-37985Processor Optimization Removal or Modification of Security-critical Code in Microsoft Windows 11 Version 22h2

Severity
5.6MEDIUMNVD
EPSS
0.8%
top 26.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 17
Latest updateSep 18

Description

Windows Kernel Information Disclosure Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:NExploitability: 1.1 | Impact: 4.0

Affected Packages6 packages

NVDmicrosoft/windows_11_22h2< 10.0.22621.3880
NVDmicrosoft/windows_11_23h2< 10.0.22631.3880
CVEListV5microsoft/windows_11_version_22h210.0.22621.010.0.22621.3880
CVEListV5microsoft/windows_11_version_22h310.0.22631.010.0.22631.3880

Patches

🔴Vulnerability Details

1
GHSA
GHSA-gmhf-wxx8-x9jm: Windows Kernel Information Disclosure Vulnerability2024-09-18

📋Vendor Advisories

1
Microsoft
Windows Kernel Information Disclosure Vulnerability2024-07-09

🕵️Threat Intelligence

6
Trendmicro
The July 2024 Security Update Review2024-07-09
Qualys
Microsoft and Adobe Patch Tuesday, July 2024 Security Update Review2024-07-09
Trendmicro
The July 2024 Security Update Review2024-07-09
Qualys
Microsoft and Adobe July 2024 Security Patches Explained | Qualys2024-07-09
Crowdstrike
July 2024 Patch Tuesday: Updates and Analysis
CVE-2024-37985 — Microsoft vulnerability | cvebase