CVE-2024-30098

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jul 9, 2024
Updated: Jul 17, 2024
CWE ID 327

Summary

CVE-2024-30098 is a newly disclosed vulnerability affecting Windows Cryptographic Services. This security feature bypass issue permits an attacker to manipulate the encryption and decryption process, potentially leading to unauthorized access to sensitive data. The vulnerability can be exploited remotely, making it a serious threat to organizations and individuals using unpatched Windows systems. Microsoft has released a security update to address this issue, and it is strongly recommended that users install the patch as soon as possible to mitigate the risk. Failure to do so may result in the exposure of confidential information or unauthorized system access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share