CVE-2024-20696: Windows libarchive Remote Code Execution Vulnerability
Last updated 31 October 2024
Other sources
Windows libarchive Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libarchiveto a version that resolves this vulnerability.Fixed in 3.7.4-1.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.3007Patch KB5034123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.643Patch KB5034130 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.3007Patch KB5034123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.3930Patch KB5034122 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.3930Patch KB5034122 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2713Patch KB5034121 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2227Patch KB5034129 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.5329Patch KB5034127
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20696?
CVE-2024-20696 is rated as critical, as it allows for remote code execution on the affected systems.
How do I fix CVE-2024-20696?
To mitigate CVE-2024-20696, apply the relevant security updates available from Microsoft for your affected Windows version.
What versions of Windows are affected by CVE-2024-20696?
CVE-2024-20696 affects multiple versions including Windows Server 2019, Windows Server 2022, and Windows 10 and 11 in specific builds.
Is CVE-2024-20696 a local or remote vulnerability?
CVE-2024-20696 is a remote code execution vulnerability, allowing attackers to execute arbitrary code from a remote location.
Are there any known exploits for CVE-2024-20696?
At this time, there are no publicly reported exploits for CVE-2024-20696, but immediate patching is recommended to prevent potential attacks.