ZeroHour

CVE-2024-43452

mass

Microsoft Windows Registry TOCTOU Race Condition Allows Elevation of Privilege

CVSS 3.1
7.5 high
EPSS
28%p98
Published
()
Modified
AI analysis

CVE-2024-43452 is an elevation of privilege vulnerability in the Microsoft Windows Registry caused by a time-of-check to time-of-use (TOCTOU) race condition (CWE-367). The CVSS vector (AV:N/AC:H/PR:N/UI:R) indicates the flaw is scored with a network trigger requiring user interaction, and because it is a race condition with high attack complexity, exploitation requires winning a timing race between a registry security check and the registry operation. An attacker who wins that race can make unauthorized registry changes with elevated rights, effectively escalating to administrator/SYSTEM-level privileges, typically as the second stage of a chain after initial code execution. All currently supported Windows client releases (Windows 10 1809/21H2/22H2, Windows 11 22H2/23H2/24H2) and Windows Server releases (2008, 2019, 2022, 2022 23H2, 2025) are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known and the issue is not in CISA's KEV catalog, but EPSS assigns a high 28.1% (98th percentile) probability of exploitation within the next 30 days.

What to do: Deploy Microsoft's security update for CVE-2024-43452 (November 2024) across all affected Windows 10/11 and Windows Server hosts, prioritizing multi-user systems such as RDS/session hosts and shared workstations where local privilege escalation is most impactful. No public workaround is known; until patched, enforce least-privilege accounts and caution around untrusted content or actions that trigger registry operations. Given the elevated EPSS score (28.1% within 30 days), monitor Microsoft advisories and threat intelligence for signs of weaponization.

Affected
microsoft Windows 101809, 21H2, 22H2
microsoft Windows 1122H2, 23H2, 24H2
microsoft Windows Server2008, 2019, 2022, 2022 23H2, 2025
Estimated exposure
mass≈1 billion+ Windows devices/servers (every currently supported Windows 10/11 client and Windows Server release is affected) — Windows runs on more than a billion active devices, and the affected-product list spans the entire currently supported Windows client and Server line, so the plausibly affected population is effectively the whole supported Windows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Registry Elevation of Privilege Vulnerability

Vendors
microsoft
Products
windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2019, windows server 2022, windows server 2022 23h2, windows server 2025
Weakness
CWE-367
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.