Vulnerability record · CVE-2024-43642 · published 12 November 2024
CVE-2024-43642: Windows SMB use-after-free denial of service
Microsoft · Windows 11 22h2
CVE-2024-43642 is a use-after-free flaw in Windows SMB that lets an unauthenticated remote attacker crash the service. Microsoft rates it high severity (CVSS 7.5), and the affected products are Windows 11 22H2/23H2/24H2 and Windows Server 2022, 2022 23H2 and 2025. The description is thin, so the exact trigger path is not documented in this record.
Description
Windows SMB Denial of Service Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote availability impact on widely deployed Windows SMB with very high EPSS, though no confirmed in-the-wild exploitation is recorded.
What it is
CVE-2024-43642 is a use-after-free flaw in Windows SMB that lets an unauthenticated remote attacker crash the service. Microsoft rates it high severity (CVSS 7.5), and the affected products are Windows 11 22H2/23H2/24H2 and Windows Server 2022, 2022 23H2 and 2025. The description is thin, so the exact trigger path is not documented in this record.
Impact
An attacker can cause a denial of service against the SMB service, disrupting file sharing and related Windows services on the target host. There is no stated confidentiality or integrity impact; the vector shows availability only.
Attack surface
Reachable over the network via SMB (AV:N) with no authentication and no user interaction (PR:N/UI:N), so any host exposing SMB is a candidate target. The record does not specify which SMB operation or packet triggers the flaw.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in this record, but EPSS is very high at 0.627 (99th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2024-43642 as soon as possible.
- Restrict SMB exposure to trusted networks and block TCP 445 and 139 at perimeter and inter-segment boundaries where not required.
- Disable SMBv1 and any unused SMB services or shares to reduce the attack surface.
- Monitor SMB service crashes and unexpected restarts on affected Windows 11 and Windows Server hosts.
Detection
- Alert on SMB service (LanmanServer) crashes, unexpected terminations or automatic restarts in Windows event logs.
- Watch for repeated SMB connection attempts or malformed SMB traffic from single sources against port 445.
- Correlate host availability drops or share-access failures with SMB-related error events on affected builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43642 | PatchVendor Advisory |
Track CVE-2024-43642 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-43642), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.