CVE-2024-43447
published 2024-11-12CVE-2024-43447: Windows SMBv3 Server Remote Code Execution Vulnerability
PriorityP351high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.42%
69.7th percentile
Windows SMBv3 Server Remote Code Execution Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2022 | < 10.0.20348.2849 | 10.0.20348.2849 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.2849 | 10.0.20348.2849 |
| msrc | windows_server_2022 | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows SMBv3 Server Remote Code Execution Vulnerability
vendor_msrc·2024-11-12·CVSS 8.1
CVE-2024-43447 [HIGH] CWE-415 Windows SMBv3 Server Remote Code Execution Vulnerability
Windows SMBv3 Server Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
To successfully exploit this vulnerability, an attacker would need to use a malicious SMB client to mount an attack against the SMB server. This exploit is only applicable to SMB over QUIC.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment and take additional actions prior to exploitation to prepare the target environment.
Windows SMBv3 Client/Server: Windows SMBv3 Client/Server
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed
GHSA
GHSA-qx56-hjgg-8xgm: Windows SMBv3 Server Remote Code Execution Vulnerability
ghsa_unreviewed·2024-11-12
CVE-2024-43447 [HIGH] CWE-415 GHSA-qx56-hjgg-8xgm: Windows SMBv3 Server Remote Code Execution Vulnerability
Windows SMBv3 Server Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
2024-11-12
Published