CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-43634

Medium Severity
Microsoft
SVRS
30/100

CVSSv3
6.8/10

EPSS
0.0013/1

CVE-2024-43634 is a Windows USB Video Class System Driver Elevation of Privilege Vulnerability. This vulnerability allows an attacker to gain elevated privileges on a vulnerable system. Although the CVSS score is 6.8, the SOCRadar Vulnerability Risk Score (SVRS) is 30, indicating a lower immediate threat level despite being observed "In The Wild." Exploiting this vulnerability could lead to unauthorized access and control over a compromised machine. The driver flaw (CWE-125) could be triggered by a specially crafted USB device. While not critical based on SVRS, continuous monitoring is advisable to prevent potential risks. Keeping systems patched with the latest updates from the vendor advisory is essential to mitigate this vulnerability.

In The Wild
Vendor-advisory
CVSS:3.1
AV:P
AC:L
PR:N
UI:N
S:U
C:H
I:H
A:H
E:U
RL:O
RC:C
2024-11-12

2025-01-30

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

The November 2024 Security Update Review
Dustin Childs2025-02-01
The November 2024 Security Update Review | It’s not quite the holiday season, despite what some early decorators will have you believe. It is the second Tuesday of the month, and that means Adobe and Microsoft have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts.If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for November 2024<
zerodayinitiative.com
rss
forum
news
Patch Tuesday - November 2024
Adam Barnett2024-11-12
Patch Tuesday - November 2024 | 4 zero-days. AD CS ESC15 aka EKUwu. NTLMv2 disclosure. Exchange sender spoofing. Task scheduler EoP. .NET &amp; Kerberos critical RCEs. Welcome Server 2025.Microsoft is addressing 90 vulnerabilities this November 2024 Patch Tuesday. Microsoft has evidence of in-the-wild exploitation and/or public disclosure for four of the vulnerabilities published today, although as with last month’s batch, it does not evaluate any of these <a href="https://www.rapid7.com/fundamentals/zero-day-attack/
rapid7.com
rss
forum
news
1.771
2024-11-13
1.771 | Newly Added (103)Atlassian Confluence Server CVE-2019-20406 Privilege Escalation VulnerabilityAtlassian Confluence Server CVE-2023-22505 Remote Code Execution VulnerabilityAtlassian Confluence Server CVE-2024-21674 Code Injection VulnerabilityAtlassian
fortiguard.com
rss
forum
news

Social Media

CVE-2024-43634 Windows USB Video Class System Driver Elevation of Privilege Vulnerability https://t.co/Cg8wfuyvVB
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
OSMicrosoftwindows_10_1809
OSMicrosoftwindows_10_21h2
OSMicrosoftwindows_10_22h2
OSMicrosoftwindows_10_1607
OSMicrosoftwindows_11_22h2
OSMicrosoftwindows_10_1507
OSMicrosoftwindows_server_2022
OSMicrosoftwindows_server_2012
OSMicrosoftwindows_server_2016
OSMicrosoftwindows_11_23h2
OSMicrosoftwindows_server_2022_23h2
OSMicrosoftwindows_server_2019
OSMicrosoftwindows_server_2008

References

ReferenceLink
[email protected]https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43634
WINDOWS USB VIDEO CLASS SYSTEM DRIVER ELEVATION OF PRIVILEGE VULNERABILITYhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43634

CWE Details

CWE IDCWE NameDescription
CWE-125Out-of-bounds ReadThe software reads data past the end, or before the beginning, of the intended buffer.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence