CVE-2024-43547
Windows Kerberos Information Disclosure Vulnerability
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C
- EPSS probability
- 0.65%
- CWE
- CWE-325
- Published
- 2024-10-08
- Last modified
- 2026-08-19
Affected products
- Microsoft Windows 10 Version 1809
- Microsoft Windows Server 2019
- Microsoft Windows Server 2019 (Server Core installation)
- Microsoft Windows Server 2022
- Microsoft Windows 11 version 21H2
- Microsoft Windows 10 Version 21H2
- Microsoft Windows 11 version 22H2
- Microsoft Windows 10 Version 22H2
Weakness type
Related vulnerabilities
- CVE-2020-15086 — Potential Remote Code Execution in TYPO3 with mediace extension
- CVE-2026-22863 — Deno node:crypto doesn't finalize cipher
- CVE-2020-15098 — Missing Required Cryptographic Step Leading to Sensitive Information Disclosure in TYPO3 CMS
- CVE-2025-30147 — ALTBN128_ADD, ALTBN128_MUL, ALTBN128_PAIRING precompile functions do not check if points are on curve
- CVE-2018-5383 — Bluetooth implementations may not sufficiently validate elliptic curve parameters during Diffie-Hellman key exchange
- CVE-2026-4601 — Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.sig
- CVE-2023-46129 — xkeys Seal encryption used fixed key for all encryption
- CVE-2022-20742 — Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPsec IKEv2 VPN Information Disclosure Vulnerability