Critical CVSS 9.8 EPSS 0.12132 ⚠️ Exploited in the wild 2024-09 archive

Executive Summary

Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.

Overview

9.8
CVSS CRITICAL
Critical
MS Severity
Exploited
MS Exploit Status
Exploitation Detected
MS Exploit Likelihood
Category Remote Code Execution
Released Sep 10 2024
Last Updated Sep 10 2024
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.12132 — 0.95626 percentile
NVD CVSS 9.8 CRITICAL — matches MSRC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Functional
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 9.1

EPSS Score

0.12132
probability of exploitation in the next 30 days
0.95626 percentile - updated 2026-06-21
View on FIRST.org

Affected Products

2 affected products
Product KB Article Severity Impact Restart Required
Windows 10 for 32-bit Systems 5043083 (Security Update) Critical Remote Code Execution Yes
Windows 10 for x64-based Systems 5043083 (Security Update) Critical Remote Code Execution Yes

Patches

1 patch
Article Type Restart
5043083 Security Update Yes

Known Exploits

Acknowledgments

Anonymous