CVE-2024-49019 — Weak Authentication in Microsoft Windows Server 2008 R2 Service Pack 1
Severity
7.8HIGHNVD
EPSS
4.7%
top 10.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateApr 8
Description
Active Directory Certificate Services Elevation of Privilege Vulnerability
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages9 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1🕵️Threat Intelligence
10Talos▶
November Patch Tuesday release contains three critical remote code execution vulnerabilities↗2024-11-12