VDB
BDU%3A2024-01320
BDU%3A2024-01320
PUBLISHED
CVSS 9.399999618530273 CRITICAL
Уязвимость функции Internet Shortcut Files Security операционных систем Windows, позволяющая нарушителю обойти существующие ограничения безопасности
Risk Scores
CVSS 2.0
9.399999618530273
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp | Windows 10 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 21H2, Windows 11 22H2, Windows 10 22H2, Windows 11 21H2, Windows 11 23H2, Windows Server 2022, 23H2 Edition (Server Core installation) |
Timeline
- Feb 15, 2024 CVE Published
- Mar 18, 2025 PoC Published
- Apr 7, 2025 CVE Updated
- Jun 15, 2025 PoC Published
- Mar 19, 2026 Security Advisory
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21412 url
- https://www.cybersecurity-help.cz/vdb/SB2024021335 url
- https://www.trendmicro.com/en_us/research/24/c/cve-2024-21412--darkgate-operators-exploit-microsoft-windows-sma.html url
- https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv url