CVE-2024-43527 is a Windows Kernel Elevation of Privilege vulnerability affecting Microsoft Windows 11 24H2. It carries a high CVSS score of 7.8, indicating that a local attacker with low privileges can achieve high impact on confidentiality, integrity, and availability with low attack complexity. While not currently listed in CISA's KEV catalog, there are no public exploits available on Metasploit, Nuclei, or ExploitDB. Despite limited community discussion and media coverage, Microsoft addressed this flaw in their October 2024 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.26100.2033CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.26100.2033CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.