← Vulnerability feed

Vulnerability record · CVE-2024-43642 · published 12 November 2024

CVE-2024-43642: Windows SMB use-after-free denial of service

Microsoft · Windows 11 22h2

CVE-2024-43642 is a use-after-free flaw in Windows SMB that lets an unauthenticated remote attacker crash the service. Microsoft rates it high severity (CVSS 7.5), and the affected products are Windows 11 22H2/23H2/24H2 and Windows Server 2022, 2022 23H2 and 2025. The description is thin, so the exact trigger path is not documented in this record.

7.5 CVSS 3.1 High EPSS 63% · top 0.8% CWE-416 · Use after free
7.5CVSS 3.1 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Windows SMB Denial of Service Vulnerability

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote availability impact on widely deployed Windows SMB with very high EPSS, though no confirmed in-the-wild exploitation is recorded.

What it is

CVE-2024-43642 is a use-after-free flaw in Windows SMB that lets an unauthenticated remote attacker crash the service. Microsoft rates it high severity (CVSS 7.5), and the affected products are Windows 11 22H2/23H2/24H2 and Windows Server 2022, 2022 23H2 and 2025. The description is thin, so the exact trigger path is not documented in this record.

Impact

An attacker can cause a denial of service against the SMB service, disrupting file sharing and related Windows services on the target host. There is no stated confidentiality or integrity impact; the vector shows availability only.

Attack surface

Reachable over the network via SMB (AV:N) with no authentication and no user interaction (PR:N/UI:N), so any host exposing SMB is a candidate target. The record does not specify which SMB operation or packet triggers the flaw.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware use is documented in this record, but EPSS is very high at 0.627 (99th percentile), indicating elevated predicted exploitation activity.

What to do

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2024-43642 as soon as possible.
  • Restrict SMB exposure to trusted networks and block TCP 445 and 139 at perimeter and inter-segment boundaries where not required.
  • Disable SMBv1 and any unused SMB services or shares to reduce the attack surface.
  • Monitor SMB service crashes and unexpected restarts on affected Windows 11 and Windows Server hosts.

Detection

  • Alert on SMB service (LanmanServer) crashes, unexpected terminations or automatic restarts in Windows event logs.
  • Watch for repeated SMB connection attempts or malformed SMB traffic from single sources against port 445.
  • Correlate host availability drops or share-access failures with SMB-related error events on affected builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-43642 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-33824Double free in Windows IKE Extension enables remote code executionA double free flaw (CWE-415) exists in the Windows IKE Extension, reachable over the network by an unauthenticated attacker. Successful exploitation …KEVEPSS 1.6%analysed9.8CVE-2025-59287Microsoft WSUS deserialization flaw allows unauthenticated remote code executionWindows Server Update Service (WSUS) deserializes untrusted data, letting an unauthenticated network attacker run code on the server. The flaw is rat…KEVEPSS 100%analysed8.8CVE-2026-21510Windows Shell protection mechanism failure allows security feature bypassWindows Shell contains a protection mechanism failure (CWE-693) that lets an unauthorized attacker bypass a security feature over a network. The flaw…KEVEPSS 24%analysed8.8CVE-2026-21513Microsoft MSHTML security feature bypass on WindowsCVE-2026-21513 is a protection mechanism failure (CWE-693) in the Microsoft MSHTML Framework that lets an unauthorized attacker bypass a security fea…KEVEPSS 16%analysed8.8CVE-2025-33073Windows SMB improper access control allows privilege elevationWindows SMB contains an improper access control flaw (CWE-284) that lets an authorized attacker elevate privileges over the network. Microsoft rates …KEVEPSS 83%analysed8.8CVE-2025-33053Microsoft Windows WebDAV Internet Shortcut File Path Control RCEWindows Internet Shortcut (.url) files allow external control of a file name or path, which an unauthorized attacker can abuse to execute code over a…KEVEPSS 87%analysed8.8CVE-2024-49039Windows Task Scheduler elevation of privilege via improper authenticationCVE-2024-49039 is an elevation of privilege flaw in the Windows Task Scheduler, classified as improper authentication (CWE-287). A local attacker wit…KEVEPSS 14%analysed8.8CVE-2024-43461Windows MSHTML Platform spoofing flaw enables code executionCVE-2024-43461 is a spoofing vulnerability in the Windows MSHTML platform, the legacy rendering engine still reachable through Windows components. Th…KEVEPSS 54%analysed

Source: NIST National Vulnerability Database (record CVE-2024-43642), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.