CVE-2024-43545: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27366Patch KB5044321 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22918Patch KB5044306 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25118Patch KB5044342 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22221Patch KB5044343 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7428Patch KB5044293 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.6414Patch KB5044277 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2762Patch KB5044281 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1189Patch KB5044288
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43545?
CVE-2024-43545 has been assigned a severity rating by Microsoft based on its impact on systems running affected versions.
How do I fix CVE-2024-43545?
To fix CVE-2024-43545, install the latest patches released by Microsoft for your affected Windows Server version.
What systems are affected by CVE-2024-43545?
CVE-2024-43545 affects various versions of Windows Server including 2008, 2012, 2016, 2019, and 2022.
Can CVE-2024-43545 cause a denial of service?
Yes, CVE-2024-43545 can lead to a denial of service on systems using the Windows Online Certificate Status Protocol (OCSP) Server.
Are there any known exploits for CVE-2024-43545?
As of now, there are no public exploits specifically targeting CVE-2024-43545 reported.