PT-2024-7395 · Microsoft · Windows Remote Registry Client+1

Stiv Kupchik

·

Published

2024-02-01

·

Updated

2026-06-01

·

CVE-2024-43532

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Windows Remote Registry client (affected versions not specified)
Description: The issue is related to the Windows Remote Registry client, where an elevation of privilege vulnerability exists due to the use of outdated transport protocols, allowing an attacker to relay NTLM authentication and potentially gain control over a Windows domain. This vulnerability can be exploited by an attacker to intercept and relay NTLM authentication, affecting the system. The estimated number of potentially affected devices worldwide is not specified. There have been reports of real-world incidents where this issue was exploited.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

LPE

Weakness Enumeration

Related Identifiers

BDU:2024-08765
CVE-2024-43532

Affected Products

Windows
Windows Remote Registry Client