CVE-2024-43572
Microsoft Management Console Remote Code Execution Vulnerability
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
- EPSS probability
- 66.70%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-707
- Published
- 2024-10-08
- Last modified
- 2026-08-19
Affected products
- Microsoft Windows 10 Version 1809
- Microsoft Windows Server 2019
- Microsoft Windows Server 2019 (Server Core installation)
- Microsoft Windows Server 2022
- Microsoft Windows 11 version 21H2
- Microsoft Windows 10 Version 21H2
- Microsoft Windows 11 version 22H2
- Microsoft Windows 10 Version 22H2
Weakness type
Related vulnerabilities
- CVE-2024-10915 — D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
- CVE-2024-10914 — D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
- CVE-2023-46689 — Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to pote
- CVE-2023-42773 — Improper neutralization in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to po
- CVE-2026-20330 — Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Neutralization Vulnerabilities
- CVE-2026-76443 — Cisco Secure Email Gateway Security Hardening Release
- CVE-2026-18613 — GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection
- CVE-2026-5002 — PromtEngineer localGPT LLM Prompt server.py _route_using_overviews injection