CVE-2024-43450
published 2024-11-12CVE-2024-43450: Windows DNS Spoofing Vulnerability Windows DNS Spoofing Vulnerability
high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
0.56%
43.1th percentile
Windows DNS Spoofing Vulnerability
Windows DNS Spoofing Vulnerability
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27415 | 6.1.7601.27415 |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25165 | 6.2.9200.25165 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22267 | 6.3.9600.22267 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.7515 | 10.0.14393.7515 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.6532 | 10.0.17763.6532 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.2849 | 10.0.20348.2849 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.2314 | 10.0.26100.2314 |
| msrc | windows_server_2008_r2_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_2022_23h2_edition | — | — |
| msrc | windows_server_2025 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
cvelistv57.5HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CVEList
Windows DNS Spoofing Vulnerability
cvelistv5·2024-11-12·CVSS 7.5
CVE-2024-43450 [HIGH] CWE-924 Windows DNS Spoofing Vulnerability
Windows DNS Spoofing Vulnerability
Windows DNS Spoofing Vulnerability
Microsoft
Windows DNS Spoofing Vulnerability
vendor_msrc·2024-11-12·CVSS 7.5
CVE-2024-43450 [HIGH] CWE-924 Windows DNS Spoofing Vulnerability
Windows DNS Spoofing Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
The attacker must inject themselves into the logical network path between the target and the resource requested by the victim to read or modify network communications. This is called a machine-in-the-middle (MITM) attack.
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required are none (PR:N). What does that mean for this vulnerability?
An unauthorized attacker must wait for a user to initiate a connection.
Microsoft Windows DNS: Microsoft Windows DNS
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exp
No detection rules found.
No public exploits indexed.
2024-11-12
Published