KEV · Actively exploited
CVE-2024-43451
HIGH 6.5
KEV
NTLM Hash Disclosure Spoofing Vulnerability
EPSS
90.31%
exploit likely
percentile 99.6%
CISA Known Exploited Vulnerability
- Added to KEV
- 2024-11-12
- Remediation deadline
- 2024-12-03
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Ransomware
- No
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Fixed in Windows Server 2025 (Server Core installation) 10.0.26100.2314 Windows Server 2025 10.0.26100.2314 Windows Server 2022 (Server Core installation) 10.0.20348.2849 Windows Server 2022 10.0.25398.1251 Windows Server 2019 (Server Core installation) 10.0.17763.6532 Windows Server 2019 10.0.17763.6532 Windows Server 2016 (Server Core installation) 10.0.14393.7515 Windows Server 2016 10.0.14393.7515 Windows 11 24H2 · 2024-H2 10.0.26100.2314 Windows 11 23H2 · 2023-H2 10.0.22631.4460 Windows 11 22H2 · 2022-H2 10.0.22621.4460 Windows 10 22H2 · 2022-H2 10.0.19045.5131 Windows 10 21H2 · 2021-H2 10.0.19044.5131 Windows 10 1809 · 2018-09 10.0.17763.6532 Windows 10 1607 · 2016-07 10.0.14393.7515