PT-2024-6050 · Microsoft · Windows 10+1
Published
2024-09-10
·
Updated
2026-02-21
·
CVE-2024-43491
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows 10 version 1507
Description
The vulnerability is related to a servicing stack issue that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507. This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 systems that have installed the Windows security update released on March 12, 2024, or other updates released until August 2024. The vulnerability allows remote attackers to execute arbitrary code.
Recommendations
To address this vulnerability, install the September 2024 Servicing stack update (SSU KB5043936) and the September 2024 Windows security update (KB5043083), in that order.
Fix
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 10