CVE-2024-49117 is a critical Remote Code Execution (RCE) vulnerability affecting Microsoft Windows Hyper-V, impacting Windows 11 (22H2, 23H2, 24H2) and Windows Server (2022, 2022 23H2, 2025). With a CVSS score of 8.8 (High), it allows a low-privileged attacker to achieve RCE with high impact on confidentiality, integrity, and availability, though it requires local access and no user interaction. While not currently listed in CISA's KEV catalog or having public exploit code (Metasploit, Nuclei, ExploitDB), its high FAUCET Risk Score of 70/100, significant community discussion, and media coverage indicate considerable attention and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.22621.4602CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22631.4602CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:* | ||
< 10.0.26100.2605CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:* | ||
< 10.0.20348.2966CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* | ||
< 10.0.25398.1308CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.