ZeroHour

CVE-2024-43642

mass

Unauthenticated use-after-free DoS in Windows SMB (Windows 11 / Windows Server)

CVSS 3.1
7.5 high
EPSS
63%p99
Published
()
Modified
AI analysis

CVE-2024-43642 is a use-after-free flaw (CWE-416) in the SMB implementation of Windows that allows an unauthenticated remote attacker to send specially crafted SMB network traffic and crash the affected service. Because the CVSS vector is network-exploitable with low complexity, no privileges and no user interaction, any host running the SMB service on an affected edition can be targeted directly. The attacker gains only availability impact (a high-severity denial of service); confidentiality and integrity are not affected. Systems running Windows 11 22H2, 23H2 or 24H2 and Windows Server 2022, 2022 23H2 or 2025 are affected until they receive the November 2024 cumulative security updates. As of the current data there is no public proof-of-concept and the flaw is not in CISA's KEV catalog, but its EPSS of 62.7% (99th percentile) indicates an elevated likelihood of exploitation attempts within 30 days.

What to do: Install the November 2024 cumulative security update for Windows 11 22H2/23H2/24H2 and Windows Server 2022/2022 23H2/2025 as soon as practical, prioritizing internet-facing and multi-user servers. Until patched, restrict inbound SMB (TCP/UDP 445) to trusted networks only via firewall rules or VPN, and monitor for crash/restart events of the SMB service on exposed hosts.

Affected
microsoft windows 11 22h2
microsoft windows 11 23h2
microsoft windows 11 24h2
microsoft windows server 2022
microsoft windows server 2022 23h2
microsoft windows server 2025
Estimated exposure
masshundreds of millions of endpoints and servers potentially in scope (Windows 11 22H2-24H2 desktop base plus Windows Server 2022/2025 fleets) — Windows 11 22H2 through 24H2 run on hundreds of millions of consumer and enterprise endpoints and Windows Server 2022/2025 are current, widely deployed server editions, so any of those hosts with the SMB service enabled and reachable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows SMB Denial of Service Vulnerability

Vendors
microsoft
Products
windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2022, windows server 2022 23h2, windows server 2025
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news