CVE-2023-24941
Microsoft Windows Server 2012 r2
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2023-24941 is a critical-severity Use of Uninitialized Resource (CWE-908) vulnerability in Microsoft Windows Server 2012. Its CVSS base score is 9.8 (Critical).
Operationally, exploitation aligns with the MITRE ATT&CK technique OS Credential Dumping (T1003); ranked in the top 0.1% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2023-24941 is a remote code execution vulnerability affecting the Windows Network File System component. It carries a CVSS 3.1 base score of 9.8 and is associated with CWE-908.
An unauthenticated attacker can exploit the flaw over the network to execute arbitrary code with high impact on confidentiality, integrity, and availability. No user interaction or privileges are required for successful exploitation.
Microsoft has published an advisory for the issue at the referenced MSRC update guide URL that addresses mitigation steps and available updates. The EPSS score reached a peak of 0.4389 with a current value of 0.4160.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-28928
Vulnerability Data
Windows Network File System Remote Code Execution Vulnerability
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC activities such as static analysis and code review directly prevent use of uninitialized resources while also addressing many other weaknesses.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development and acceptance can detect uninitialized resource usage through dynamic analysis and fuzzing.
Secure development life cycle mandates initialization checks and static analysis that can catch uninitialized resource use.
Application security requirements can specify mandatory initialization of variables and resources before use.
Secure system architecture and engineering principles include defensive coding practices that prevent use of uninitialized memory or objects.
Secure coding standards directly require explicit initialization of all variables and resources, substantially mitigating CWE-908.