PT-2024-7862 · Microsoft · Windows 11+3

Immortalp0Ny

+1

·

Published

2024-07-10

·

Updated

2024-12-20

·

CVE-2024-43629

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows DWM Core Library versions prior to the fixed version
Description The issue is related to an elevation of privilege vulnerability in the Windows DWM Core Library, which can be exploited to allow an attacker to gain system-level privileges. This vulnerability is associated with the indirect bypass of the process check about DWM of NtDCompositionDuplicateHandleToProcess, leading to a kernel arbitrary address write. The vulnerability affects all current versions of Windows, including Windows 10, 11, and server editions. Microsoft has released security updates to patch this vulnerability.
Recommendations For Windows DWM Core Library versions prior to the fixed version, apply the security update released by Microsoft to patch the vulnerability. As a temporary workaround, consider restricting access to the DWM Core Library until the patch is applied. Avoid using the NtDCompositionDuplicateHandleToProcess function in the affected library until the issue is resolved.

Fix

LPE

Untrusted Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2024-09364
CVE-2024-43629

Affected Products

Windows
Windows 10
Windows 11
Windows Dwm Core Library