EXPOSURES › CVE-2024-43572
CVE-2024-43572
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft Windows Management Console allows remote code execution via an unspecified vulnerability, enabling attackers to compromise systems without user interaction.
This vulnerability allows remote code execution in Microsoft Windows Management Console, posing a significant risk to DIB organizations relying on Windows-based systems for sensitive data. The lack of specific details on the exploit mechanism makes it difficult to assess the full scope of the impact, but the potential for unauthorized access to sensitive information is high. DIB organizations should immediately apply the latest security patches and monitor for any exploitation attempts.
Shame score — The vulnerability is actively exploited and poses a significant risk to DIB organizations, but the lack of specific details on the exploit mechanism makes it difficult to assess the full scope of the impact.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |