CVE-2024-21435HighCVSS 8.8

Windows OLE Remote Code Execution Vulnerability

Published
March 12, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution? This attack requires a specially crafted file to be placed either in an online directory or in a local network location. When a victim runs this file, it loads the malicious DLL.

How could an attacker exploit this vulnerability? An unauthenticated attacker could exploit the vulnerability by placing a specially crafted file onto an online directory or in a local network location then convincing the user to open it. In a successful attack, this will then load a malicious DLL which could lead to a remote code execution.

🎯 Affected products4

  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 23H2 for ARM64-based Systems
  • Windows 11 Version 23H2 for x64-based Systems

✅ Remediation

KB5035853 (Security Update) — fixed build 10.0.22621.3296 KB5035853 (Security Update) — fixed build 10.0.22631.3296

🔗 References (3)