CVE-2024-38259 is a high-severity Remote Code Execution vulnerability affecting Microsoft Management Console (MMC) across various Windows 11 and Server 2022 versions. This vulnerability, with a CVSS score of 8.8, can be exploited remotely with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, its high community discussion and media coverage, including mentions of active exploitation in related articles, suggest significant interest. There is no public exploit code available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.22000.3197CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.22000.3197CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:x64:* | ||
< 10.0.22621.4169CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.22621.4169CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:* | ||
< 10.0.22621.4169CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.