CVE-2024-43457: Windows Setup and Deployment Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
More Likely
Patch Tuesday
2024-Sep
Released
2024-09-10
EPSS Score
2.66% (percentile: 85.8%)

FAQ

Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table? The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerabilities that affect their machine and to install the updates if they are not receiving automatic updates. Note that the general availability date for Windows 11, version 24H2 is scheduled for later this year. What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

Affected Products (2)

Windows

  • Windows 11 Version 24H2 for ARM64-based Systems
  • Windows 11 Version 24H2 for x64-based Systems

Security Updates (1)

Acknowledgments

<a href="https://infosec.exchange/@wdormann">Will Dormann</a> with <a href="https://vu.ls/">Vul Labs</a>

Revision History

  • 2024-09-10: Information published.