CVE-2024-43536
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- EPSS probability
- 0.62%
- CWE
- CWE-601
- Published
- 2024-10-08
- Last modified
- 2026-08-19
Affected products
- Microsoft Windows 10 Version 1809
- Microsoft Windows Server 2019
- Microsoft Windows Server 2019 (Server Core installation)
- Microsoft Windows 11 version 21H2
- Microsoft Windows 10 Version 21H2
- Microsoft Windows 11 version 22H2
- Microsoft Windows 10 Version 22H2
- Microsoft Windows 11 version 22H3
Weakness type
Related vulnerabilities
- CVE-2026-6795 — Open Redirect in DivvyDrive Information Technologies' DivvyDrive
- CVE-2026-54588 — Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
- CVE-2026-53662 — immich: One-click account takeover via XSS in login page continue redirect
- CVE-2026-43941 — Unvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link click
- CVE-2026-61451 — Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url
- CVE-2026-54618 — Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the user
- CVE-2026-8323 — Open Redirect in Armiya Information Technologies' Access Control System
- CVE-2026-71428 — unstructured: Server-Side Request Forgery in the URL-based partitioning