WINDOWS KERBEROS REMOTE CODE EXECUTION VULNERABILITY - CVE-2024-43639

14 Nov / 2024

Cyber Security

WINDOWS KERBEROS REMOTE CODE EXECUTION VULNERABILITY

CVE-2024-43639

What is vulnerable?

The Kerberos Authentication system in Windows Server 2012, 2016, 2019, 2022, 2025 (Server Core included)

What has happened?

Microsoft have released an update and advisory as part of the November Patching Cycle for the new vulnerability CVE-2024-43639.

This vulnerability has been assigned the CVSS 3 score of 9.8/10. The vulnerability allows an unauthenticated attacker to use a specially crafted application to leverage a cryptographic protocol vulnerability in Windows Kerberos to perform remote code execution against the target. This process does not require any user interaction and there are no workarounds to mitigate this vulnerability.

What you can do:

The remediation for this vulnerability is to apply the November Monthly Rollup Security updates relevant to the version of Windows Server being patched. Microsoft advise that there is no evidence of this being exploited in the wild, but it is expected that this vulnerability will be reverse engineered and weaponised.

Further Information:

Microsoft’s advisory for this specific vulnerability: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43639

Rapid7’s analysis for this patch cycle: https://www.rapid7.com/blog/post/2024/11/12/patch-tuesday-november-2024/

CrowdStrike’s analysis for this patch cycle: https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-november-2024/

Cythera is actively monitoring for exposure and exploitation activity for MDR and Vulnerability Management clients.

Resources

You may be interested in

Redefining Cybersecurity for Australian Law Firms: The Promise of SASE Architecture

Redefining Cybersecurity for Australian Law Firms: The Promise of SASE Architecture The Australian legal sector's increasing adoption of digita…

Read More arrow_forward

Cythera and Druva: A Strategic Alliance for Essential Eight Compliance and Beyond

For Australian companies navigating the complexities of cyber resilience, having a dependable backup solution is not just a nice-to-have, it's a…

Read More arrow_forward

Achieving Essential 8 Compliance: Why Cythera uses Automox for Patch and Office Macros Management.

At Cythera, we understand the unique cybersecurity challenges faced by Australian organisations. The Australian Signals Directorate's (ASD) Esse…

Read More arrow_forward