CVE-2024-43574: Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1189Patch KB5044288 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.4317Patch KB5044285 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.5011Patch KB5044273 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.2033Patch KB5044284 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.4317Patch KB5044285 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.5011Patch KB5044273 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.3260Patch KB5044280 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2762Patch KB5044281
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43574?
CVE-2024-43574 has been rated with high severity due to its potential for remote code execution.
How do I fix CVE-2024-43574?
To fix CVE-2024-43574, apply the relevant security patches available for your version of Windows from Microsoft.
What versions of Windows are affected by CVE-2024-43574?
CVE-2024-43574 affects Windows 10 versions 21H2 and 22H2, Windows 11 versions 21H2, 22H2, 23H2, and 24H2, as well as Windows Server 2022.
What are the potential impacts of CVE-2024-43574?
Exploitation of CVE-2024-43574 could allow an attacker to execute arbitrary code on the affected system.
Is there a known exploit for CVE-2024-43574?
As of now, there are no public exploits known for CVE-2024-43574, but the high severity indicates that vulnerabilities may be developed.