Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
History

Tue, 10 Dec 2024 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_server_2008_R2:6.1.7601.27366:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2008_sp2:6.0.6003.22918:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2008_sp2:6.0.6003.22918:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2012:6.2.9200.25118:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:6.3.9600.22221:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:10.0.14393.7428:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.6414:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348..2762:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_23h2:10.0.25398.1189:*:*:*:*:*:*:*
Vendors & Products Microsoft windows Server 2008 R2
Microsoft windows Server 2008 Sp2
Microsoft windows Server 2012 R2
Microsoft windows Server 23h2

Thu, 17 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2008
Microsoft windows Server 2022 23h2
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
Vendors & Products Microsoft windows Server 2008
Microsoft windows Server 2022 23h2

Tue, 08 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Oct 2024 17:45:00 +0000

Type Values Removed Values Added
Description Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
Title Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows Server 2008 R2
Microsoft windows Server 2008 Sp2
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 23h2
Weaknesses CWE-400
CPEs cpe:2.3:o:microsoft:windows_server_2008_R2:6.1.7601.27366:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2008_sp2:6.0.6003.22918:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2008_sp2:6.0.6003.22918:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2012:6.2.9200.25118:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:6.3.9600.22221:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:10.0.14393.7428:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.6414:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348..2762:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_23h2:10.0.25398.1189:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows Server 2008 R2
Microsoft windows Server 2008 Sp2
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 23h2
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published: 2024-10-08T17:35:56.761Z

Updated: 2024-12-10T18:46:07.748Z

Reserved: 2024-08-14T01:08:33.535Z

Link: CVE-2024-43545

cve-icon Vulnrichment

Updated: 2024-10-08T18:40:56.319Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-08T18:15:19.690

Modified: 2024-10-17T19:55:41.200

Link: CVE-2024-43545

cve-icon Redhat

No data.