VDB
BDU%3A2024-08765
BDU%3A2024-08765
PUBLISHED
CVSS 9 CRITICAL
Уязвимость функции BaseBindToMachine() библиотеки advapi32.dll клиента WinReg операционных систем Windows, позволяющая нарушителю повысить свои привилегии
Risk Scores
CVSS 2.0
9
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp | Windows Server 2008 Service Pack 2, Windows Server 2012, Windows Server 2012 R2, Windows Server 2008 R2 Service Pack 1, Windows 10, Windows Server 2008 R2 Service Pack 2, Windows 10 1607, Windows Server 2016, Windows Server 2008 Service Pack 2 (Server Core Installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows 10 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2008 R2 Service Pack 2 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 21H2, Windows 11 22H2, Windows 10 22H2, Windows 11 21H2, Windows Server 2012 (Server Core installation), Windows 11 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 24H2 |
Timeline
- Oct 30, 2024 CVE Published
- Mar 19, 2026 Security Advisory
References
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43532 url
- https://vuldb.com/?id.279705 url
- https://www.cybersecurity-help.cz/vdb/SB2024100890 url
- https://github.com/akamai/akamai-security-research/tree/main/PoCs/cve-2024-43532 url
- https://securityonline.info/critical-eop-flaw-in-microsofts-remote-registry-researcher-publishes-poc-for-cve-2024-43532/ url
- https://www.akamai.com/blog/security-research/winreg-relay-vulnerability url
- https://www.securitylab.ru/news/553177.php url