PT-2024-6050 · Microsoft · Windows 10+1

Published

2024-09-10

·

Updated

2026-02-21

·

CVE-2024-43491

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows 10 version 1507
Description The vulnerability is related to a servicing stack issue that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507. This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 systems that have installed the Windows security update released on March 12, 2024, or other updates released until August 2024. The vulnerability allows remote attackers to execute arbitrary code.
Recommendations To address this vulnerability, install the September 2024 Servicing stack update (SSU KB5043936) and the September 2024 Windows security update (KB5043083), in that order.

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2024-06872
CVE-2024-43491

Affected Products

Windows
Windows 10