#VU98224 Use of uninitialized resource in Windows - CVE-2024-43502

 

#VU98224 Use of uninitialized resource in Windows - CVE-2024-43502

Published: October 8, 2024


Vulnerability identifier: #VU98224
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-43502
CWE-ID: CWE-908
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Windows
Software vendor:
Microsoft

Description

The vulnerability allows a local user to bypass certain security restrictions.

The vulnerability exists due to usage of uninitialized resources in Windows Kernel. A local user can pass specially crafted data to the application, trigger uninitialized usage of resources and gain elevated privileges on the target system.


Remediation

Install updates from vendor's website.

External links