CVE-2024-43571HighCVSS 5.6

Sudo for Windows Spoofing Vulnerability

Published
October 8, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, user interaction is required (UI:R) and privileges required are low (PR:L). What does that mean for this vulnerability? An authenticated attacker must launch a specially crafted malicious application and wait for the victim to perform a command in a console window for the vulnerability to be exploited.

🎯 Affected products2

  • Windows 11 Version 24H2 for ARM64-based Systems
  • Windows 11 Version 24H2 for x64-based Systems

✅ Remediation

KB5044284 (Security Update) — fixed build 10.0.26100.2033

🔗 References (3)