CVE-2024-43607: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7428Patch KB5044293 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.6414Patch KB5044277 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22221Patch KB5044343 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27366Patch KB5044321 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25118Patch KB5044342 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22918Patch KB5044306 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1189Patch KB5044288 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2762Patch KB5044281
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43607?
CVE-2024-43607 has been assessed with a critical severity rating due to its potential to allow remote code execution.
How do I fix CVE-2024-43607?
To mitigate CVE-2024-43607, apply the latest security updates and patches provided by Microsoft for affected Windows Server versions.
Which versions of Windows are affected by CVE-2024-43607?
CVE-2024-43607 affects multiple versions of Windows Server, including 2008, 2012, 2016, 2019, 2022, and their respective Server Core installations.
What is the impact of CVE-2024-43607?
The impact of CVE-2024-43607 is significant, as it could allow an attacker to execute arbitrary code on the vulnerable system.
What is the CVSS score for CVE-2024-43607?
CVE-2024-43607 has a CVSS score that reflects its critical risk, which indicates a high level of threat to affected systems.