CVE-2024-38193
Windows Ancillary Function Driver for WinSock Schwachstelle zur Erhöhung von Berechtigungen
Aktiv ausgenutzt
- Seit dem 13. Aug. 2024 im CISA-Katalog ausgenutzter Schwachstellen
- US-Bundesbehörden müssen sie bis zum 3. Sept. 2024 beheben (BOD 22-01)
- Angegriffen 1 Tag bevor die Schwachstelle öffentlich wurde
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Quelle: CISA KEV · 21. Aug. 2026 20. Nov. 2025 19. Nov. 2025 21. Feb. 2025 11. Feb. 2025 19. Nov. 2024
CVSS-Score7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSchwachstellentyp (CWE)CWE-416
Herstellermicrosoft
Betroffene Produkte
| Hersteller | Produkt | Versionen |
|---|---|---|
| microsoft | windows 10 1507 | < 10.0.10240.20751 |
| microsoft | windows 10 1607 | < 10.0.14393.7259 |
| microsoft | windows 10 1809 | < 10.0.17763.6189 |
| microsoft | windows 10 21h2 | < 10.0.19044.4780 |
| microsoft | windows 10 22h2 | < 10.0.19045.4780 |
| microsoft | windows 11 21h2 | < 10.0.22000.3147 |
| microsoft | windows 11 22h2 | < 10.0.22621.4037 |
| microsoft | windows 11 23h2 | < 10.0.22631.4037 |
| microsoft | windows 11 24h2 | < 10.0.26100.1457 |
| microsoft | windows server 2008 | - |
| microsoft | windows server 2012 | < 6.2.9200.25031 |
| microsoft | windows server 2016 | < 10.0.14393.7259 |
| microsoft | windows server 2019 | < 10.0.17763.6189 |
| microsoft | windows server 2022 | < 10.0.20348.2655 |
| microsoft | windows server 2022 23h2 | < 10.0.25398.1085 |
Verwandte Artikel
This product uses the NVD API but is not endorsed or certified by the NVD.
Die technische Beschreibung ist unsere Übersetzung des englischen NVD-Originaltexts.
