CVE-2024-43572
KEVmass1Actively Exploited RCE in Microsoft Management Console on Windows 10, 11 and Server
CISA: Microsoft Windows Management Console Remote Code Execution Vulnerability
CVE-2024-43572 is a remote code execution vulnerability in Microsoft Management Console (MMC, mmc.exe), patched by Microsoft as an actively exploited zero-day in its October 2024 Patch Tuesday release. It is triggered when a user opens a specially crafted .msc snap-in file; the CVSS vector (AV:L/AC:L/PR:N/UI:R) confirms local delivery with user interaction, for example via a phishing attachment or downloaded file. Successful exploitation allows the attacker to execute arbitrary code in the context of the user who opened the file, with high impact on confidentiality, integrity and availability. Per the published CPE data, affected systems span Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2 through 24H2) and Windows Server 2008, 2012 and 2016, effectively the entire installed Windows base. The flaw is confirmed exploited in the wild: it was added to CISA's KEV on 2024-10-08, EPSS assigns a ~67% probability of exploitation within 30 days (99th percentile), and press coverage lists it among the two exploited zero-days fixed in October 2024.
What to do: Apply Microsoft's October 2024 (or later) security/cumulative updates to all affected Windows 10, Windows 11 and Windows Server systems, as the MMC fix ships in the monthly cumulative updates rather than as a standalone patch. Until patched, do not open .msc snap-in files from untrusted or unsolicited sources and brief users on malicious snap-in attachments. Track this against the KEV required action and prioritize deployment given confirmed in-the-wild exploitation and high EPSS.
| microsoft Windows 10 | 1507, 1607, 1809, 21H2, 22H2 |
| microsoft Windows 11 | 21H2, 22H2, 23H2, 24H2 |
| microsoft Windows Server | 2008, 2012, 2016 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Management Console Remote Code Execution Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016
- Weakness
- CWE-707
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H