cbcvebase.
CVE-2024-43642
published 2024-11-12

CVE-2024-43642: Windows SMB Denial of Service Vulnerability Windows SMB Denial of Service Vulnerability

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
61.47%
99.1th percentile
Windows SMB Denial of Service Vulnerability Windows SMB Denial of Service Vulnerability

Affected

15 ranges
VendorProductVersion rangeFixed in
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.446010.0.22621.4460
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.446010.0.22631.4460
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.446010.0.22631.4460
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.231410.0.26100.2314
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.284910.0.20348.2849
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.231410.0.26100.2314
msrcwindows_11_version_22h2_for_arm64-based_systems
msrcwindows_11_version_22h2_for_x64-based_systems
msrcwindows_11_version_23h2_for_arm64-based_systems
msrcwindows_11_version_23h2_for_x64-based_systems
msrcwindows_11_version_24h2_for_arm64-based_systems
msrcwindows_11_version_24h2_for_x64-based_systems
msrcwindows_server_2022
msrcwindows_server_2022_23h2_edition
msrcwindows_server_2025

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2024-43642 targets Windows SMB and is rated 'Exploitation More Likely' by Microsoft, making SMB traffic anomaly detection a priority — monitor for malformed or unexpected SMB packets that could trigger a denial-of-service condition on exposed Windows hosts.
  • The vulnerability is in the Windows SMB component; ensure SMB ports (445/TCP, 139/TCP) are not exposed to untrusted networks and monitor for unusual SMB connection patterns or crashes in the SMB service (srv2.sys / srvnet.sys).
  • Customer action is required — patch with the relevant KB updates (KB5046617, KB5046696, KB5046616, KB5046698, KB5046633, KB5046618) and verify deployment to reduce exploitation risk.
  • ·No public exploit code has been confirmed at time of disclosure; exploitation status may change and should be re-evaluated as new information emerges.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cvelistv57.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.