Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2024-38239 |
CWE-ID | CWE-287 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
Windows Operating systems & Components / Operating system Windows Server Operating systems & Components / Operating system |
Vendor | Microsoft |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU97058
Risk: Low
CVSSv4.0: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-38239
CWE-ID:
CWE-287 - Improper Authentication
Exploit availability: No
DescriptionThe vulnerability allows a remote user to bypass authentication process.
The vulnerability exists due to an error when processing authentication requests in Windows Kerberos. A remote administrator can bypass authentication process and gain elevated privileges on the system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsWindows: before 10 21H2 10.0.19044.4894, 10 22H2 10.0.19041.4894, 10 22H2 10.0.19045.4894, 10 1507 10.0.10240.20766, 10 1607 10.0.14393.7336, 10 1809 10.0.17763.6293, 11 21H2 10.0.22000.3197, 11 22H2 10.0.22621.4169, 11 23H2 10.0.22631.4169, 11 24H2 10.0.26100.1742
Windows Server: before 2008 R2 6.1.7601.27320, 2008 6.0.6003.22870, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2022 10.0.20348.2695, 2022 10.0.20348.2700, 2022 23H2 10.0.25398.1128
CPE2.3 External linkshttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38239
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.