ZeroHour

CVE-2024-43572

KEVmass1

Actively Exploited RCE in Microsoft Management Console on Windows 10, 11 and Server

CISA: Microsoft Windows Management Console Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
67%p99
Published
()
KEV added
AI analysis

CVE-2024-43572 is a remote code execution vulnerability in Microsoft Management Console (MMC, mmc.exe), patched by Microsoft as an actively exploited zero-day in its October 2024 Patch Tuesday release. It is triggered when a user opens a specially crafted .msc snap-in file; the CVSS vector (AV:L/AC:L/PR:N/UI:R) confirms local delivery with user interaction, for example via a phishing attachment or downloaded file. Successful exploitation allows the attacker to execute arbitrary code in the context of the user who opened the file, with high impact on confidentiality, integrity and availability. Per the published CPE data, affected systems span Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2 through 24H2) and Windows Server 2008, 2012 and 2016, effectively the entire installed Windows base. The flaw is confirmed exploited in the wild: it was added to CISA's KEV on 2024-10-08, EPSS assigns a ~67% probability of exploitation within 30 days (99th percentile), and press coverage lists it among the two exploited zero-days fixed in October 2024.

What to do: Apply Microsoft's October 2024 (or later) security/cumulative updates to all affected Windows 10, Windows 11 and Windows Server systems, as the MMC fix ships in the monthly cumulative updates rather than as a standalone patch. Until patched, do not open .msc snap-in files from untrusted or unsolicited sources and brief users on malicious snap-in attachments. Track this against the KEV required action and prioritize deployment given confirmed in-the-wild exploitation and high EPSS.

Affected
microsoft Windows 101507, 1607, 1809, 21H2, 22H2
microsoft Windows 1121H2, 22H2, 23H2, 24H2
microsoft Windows Server2008, 2012, 2016
Estimated exposure
mass≈1+ billion Windows 10/11 devices plus widespread Windows Server 2008–2016 deployments — The affected version list spans effectively all supported Windows client releases (Windows 10/11 run on over a billion devices) and Windows Server's ubiquity in enterprise environments, so the plausible footprint is the near-entire…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Management Console Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016
Weakness
CWE-707
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news