PT-2024-6251 · Microsoft · Windows Setup/Deployment+1

Will Dormann

·

Published

2024-09-10

·

Updated

2024-09-17

·

CVE-2024-43457

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Setup and Deployment (affected versions not specified)
Description The issue is related to an elevation of privilege vulnerability in the Windows Setup and Deployment component. It is associated with a lack of quotes in writing elements or search paths. Exploitation of this issue may allow an attacker to elevate their privileges. The vulnerability can be exploited by attackers to impact the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Weakness Enumeration

Related Identifiers

BDU:2024-07198
CVE-2024-43457

Affected Products

Windows
Windows Setup/Deployment