PT-2024-1017 · Microsoft · Windows Cryptographic Services+1

Published

2024-01-09

·

Updated

2024-05-29

·

CVE-2024-20682

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Cryptographic Services (affected versions not specified)
Description The issue is related to insufficient input validation in the Cryptographic Services of Windows operating systems. This can allow an attacker to execute arbitrary code. The vulnerability enables remote attackers to affect the system by executing arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Untrusted Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2024-00207
CVE-2024-20682

Affected Products

Windows
Windows Cryptographic Services