PT-2024-9468 · Microsoft · Windows

Yuki Chen

·

Published

2024-12-10

·

Updated

2025-01-22

·

CVE-2024-49126

CVSS v3.1

8.1

High

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Windows (affected versions not specified)
Description: The vulnerability in the Windows Local Security Authority Subsystem Service (LSASS) is related to the use of insecure mechanisms for handling authentication data in the operating system's memory. This issue allows remote attackers to execute arbitrary code and affect the system. The exploitation of this vulnerability can have significant consequences for the system.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Race Condition

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2024-11168
CVE-2024-49126

Affected Products

Windows