Record summary

CVE-2024-21320 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

Windows Themes Spoofing Vulnerability

Description source: GitHub Advisory

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 19, 2024 · Source: CVE List

Affected products and versions

Showing 12 of 18
ProductSourceVersion rangeStatus
CVE List10.0.10240.0 to < 10.0.10240.20402affected
CVE List10.0.14393.0 to < 10.0.14393.6614affected
CVE List10.0.17763.0 to < 10.0.17763.5329affected
10.0.0 to < 10.0.17763.5329affected
CVE List10.0.19043.0 to < 10.0.19044.3930affected
CVE List10.0.19045.0 to < 10.0.19045.3930affected
CVE List10.0.22631.0 to < 10.0.22631.3007affected
CVE List10.0.0 to < 10.0.22000.2713affected
CVE List10.0.22621.0 to < 10.0.22621.3007affected
CVE List10.0.22631.0 to < 10.0.22631.3007affected
CVE List6.2.9200.0 to < 6.2.9200.24664affected

Windows Server 2012 (Server Core installation)

Browse Microsoft / Windows Server 2012 (Server Core installation)
CVE List6.2.9200.0 to < 6.2.9200.24664affected
CVE List6.3.9600.0 to < 6.3.9600.21765affected

Proofs of concept

2

Catalogued exploits

ExploitDBMicrosoft Windows - NTLM Hash Leak Malicious Windows ThemeExploitDB exploitby Abinesh kamal K UNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubsxyrxyy/CVE-2024-21320-POCRepository PoCby sxyrxyyStars: 2Not analyzed1 file

2.7 KiB

GitHub

PoC details

References

4