LiveActive security incident?Get immediate response
CVE Record

CVE-2024-43491: Microsoft Windows Update Remote Code Execution Vulnerability

Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.

CriticalCVSS 9.8Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

A Windows servicing flaw caused earlier security fixes to stop protecting certain Optional Components. It affects only Windows 10 version 1507 systems that received specified March–August 2024 updates. Because previously closed vulnerabilities may become exploitable again, affected legacy systems require prompt corrective updates.

Executive priority

Treat affected version 1507 systems as an immediate remediation priority because the flaw can silently reverse prior security protection. Focus first on externally reachable, operationally critical, or difficult-to-replace LTSB and IoT systems. Confirm that both September 2024 updates were deployed in Microsoft's specified order.

Technical view

CVE-2024-43491 is a Servicing Stack regression affecting Windows 10 version 1507. Updates beginning with KB5035858 through August 2024 rolled back fixes for some Optional Component vulnerabilities. The CVSS 3.1 score is 9.8, with network access, low complexity, no privileges, and no user interaction. The supplied classification is CWE-416.

Likely exposure

Exposure is limited to Windows 10 version 1507, particularly Enterprise 2015 LTSB and IoT Enterprise 2015 LTSB, with affected March–August 2024 updates installed. Later Windows 10 versions are not affected. Other version 1507 editions reached end of support in 2017.

Exploitation context

The source bundle does not establish active exploitation, and the CVE is not listed as KEV. Its CVSS vector reports functional exploit maturity, but that does not prove attacks in the wild. Risk arises because the regression can reopen previously mitigated vulnerabilities, including remote-code-execution exposure.

Researcher notes

Analyze this as a security-update regression that re-exposes earlier vulnerabilities, rather than assuming one standalone exploitation path. The bundle does not enumerate the Optional Components or earlier CVEs whose fixes were rolled back. The supplied CWE-416 mapping and RCE title should therefore be interpreted alongside Microsoft's narrower affected-platform and update conditions.

Mitigation direction

  • Inventory Windows 10 version 1507 systems and identify installed Optional Components.
  • Install Servicing Stack Update KB5043936 before Windows security update KB5043083.
  • Preserve Microsoft's required installation order during automated or manual deployment.
  • Upgrade or remove unsupported Windows 10 version 1507 editions where they remain deployed.

Validation and detection

  • Verify each system's Windows edition, version, and operating-system build.
  • Identify systems with KB5035858 or subsequent updates released through August 2024.
  • Confirm KB5043936 and KB5043083 installation records, including the required order.
  • Reassess previously mitigated vulnerabilities affecting installed Optional Components.
  • Review Microsoft's advisory for later revisions or additional affected-component details.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-416: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2024-43491 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C3.95.9microsoft

Vulnerability scoring details

Base CVSS 3.1 score

9.8Critical
CVSS 3.1 vector shape for CVE-2024-43491Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
MicrosoftWindows 10 Version 150710.0.10240.0Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-416 · source CWE mapping

Use After Free

Use After Free represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.