Microsoft Management Console Remote Code Execution Vulnerability
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HMicrosoft Windows 10 1507
OSMicrosoft< 10.0.10240.20796Microsoft Windows 10 1607
OSMicrosoft< 10.0.14393.7428Microsoft Windows 10 1809
OSMicrosoft< 10.0.17763.6414Microsoft Windows 10 21h2
OSMicrosoft< 10.0.19044.5011Microsoft Windows 10 22h2
OSMicrosoft< 10.0.19045.5011Microsoft Windows 11 21h2
OSMicrosoft< 10.0.22000.3260Microsoft Windows 11 22h2
OSMicrosoft< 10.0.22621.4317Microsoft Windows 11 23h2
OSMicrosoft< 10.0.22631.4317Microsoft Windows 11 24h2
OSMicrosoft< 10.0.26100.2033Microsoft Windows Server 2008
OSMicrosoftr2Microsoft Windows Server 2012
OSMicrosoftr2Microsoft Windows Server 2016
OSMicrosoft< 10.0.14393.7428Microsoft Windows Server 2019
OSMicrosoft< 10.0.17763.6414Microsoft Windows Server 2022
OSMicrosoft< 10.0.20348.2762Microsoft Windows Server 2022 23h2
OSMicrosoft< 10.0.25398.1189
CISA KEV — detailsi
- Vendori
- Microsoft ↗
- Producti
- Windows
- Added to KEVi
- October 8, 2024
- Remediation deadline (US Federal)i
- October 29, 2024(overdue)
Required action (CISA)i
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA descriptioni
Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution.
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
⏰CISA DEADLINE: 29 października 2024
Tags
RCE
Related vulnerabilities
CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same product
Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu
CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product
RCE w Windows Server Update Service (WSUS) — deserializacja danych
CVE-2020-1350CRITICAL10.0⚠ KEVPL ✓same product
RCE w Windows DNS Server — krytyczna podatność SIGRed (CVSS 10.0)
CVE-2020-1040CRITICAL9.0⚠ KEVPL ✓same product
RCE w Hyper-V RemoteFX vGPU — błąd walidacji wejścia od gościa
CVE-2020-0646CRITICAL9.8⚠ KEVPL ✓same product
RCE w Microsoft .NET Framework — nieprawidłowa walidacja danych wejściowych