First published: Tue Jan 09 2024(Updated: )
Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2022 23H2 | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-20655 has been rated as critical due to its potential for remote code execution.
To fix CVE-2024-20655, apply the latest patches provided by Microsoft for the affected versions of Windows Server.
CVE-2024-20655 affects multiple versions including Windows Server 2008, 2012, 2016, 2019, 2022, and their respective server core installations.
CVE-2024-20655 is classified as a Remote Code Execution vulnerability via the Microsoft Online Certificate Status Protocol.
Yes, CVE-2024-20655 can be exploited remotely without user interaction, enabling the attacker to execute arbitrary code.