CVE-2024-43642
massUnauthenticated use-after-free DoS in Windows SMB (Windows 11 / Windows Server)
CVE-2024-43642 is a use-after-free flaw (CWE-416) in the SMB implementation of Windows that allows an unauthenticated remote attacker to send specially crafted SMB network traffic and crash the affected service. Because the CVSS vector is network-exploitable with low complexity, no privileges and no user interaction, any host running the SMB service on an affected edition can be targeted directly. The attacker gains only availability impact (a high-severity denial of service); confidentiality and integrity are not affected. Systems running Windows 11 22H2, 23H2 or 24H2 and Windows Server 2022, 2022 23H2 or 2025 are affected until they receive the November 2024 cumulative security updates. As of the current data there is no public proof-of-concept and the flaw is not in CISA's KEV catalog, but its EPSS of 62.7% (99th percentile) indicates an elevated likelihood of exploitation attempts within 30 days.
What to do: Install the November 2024 cumulative security update for Windows 11 22H2/23H2/24H2 and Windows Server 2022/2022 23H2/2025 as soon as practical, prioritizing internet-facing and multi-user servers. Until patched, restrict inbound SMB (TCP/UDP 445) to trusted networks only via firewall rules or VPN, and monitor for crash/restart events of the SMB service on exposed hosts.
| microsoft windows 11 22h2 | — |
| microsoft windows 11 23h2 | — |
| microsoft windows 11 24h2 | — |
| microsoft windows server 2022 | — |
| microsoft windows server 2022 23h2 | — |
| microsoft windows server 2025 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows SMB Denial of Service Vulnerability
- Vendors
- microsoft
- Products
- windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2022, windows server 2022 23h2, windows server 2025
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H