CVE-2024-29995
Microsoft Windows Server 2008 r2
Raw vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2024-29995 is a high-severity Observable Timing Discrepancy (CWE-208) vulnerability in Microsoft Windows Server 2008. Its CVSS base score is 8.1 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Password Guessing (T1110.001); ranked in the top 29% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SA-11 (Developer Testing and Evaluation) and SA-8 (Security and Privacy Engineering Principles) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2024-29995 is an elevation of privilege vulnerability in the Kerberos implementation on Windows. It received a CVSS 3.1 score of 8.1 with a vector of AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H and is also associated with CWE-208.
An unauthenticated attacker can exploit the flaw remotely over a network connection, albeit with high attack complexity, to obtain privileges sufficient to compromise confidentiality, integrity, and availability on the target system.
The sole reference points to the Microsoft Security Response Center advisory page for this CVE, which is the authoritative source for any official patches or mitigation guidance. The associated EPSS score remains low, with a current value of 0.0614 and a peak of 0.0636.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-26966
Vulnerability Data
Windows Kerberos Elevation of Privilege Vulnerability
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V11.2.4
Mitigating Controls (NIST 800-53 r5) AI
Developer testing can include timing analysis or side-channel test cases that reveal observable timing discrepancies.
Engineering principles can mandate constant-time algorithms and side-channel resistance so timing discrepancies are never introduced.
Requiring approved cryptographic modules and algorithms implicitly demands implementations free of observable timing leaks.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require constant-time implementations that eliminate observable timing discrepancies.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Consistent reference clocks limit the attacker's ability to measure or manipulate timing differences that could reveal internal state or processing paths.