Patch
CVE-2024-43572
with vRx
Vulnerability Overview
CVE Name
CVE-2024-43572
Severity
7.8
High
CVE Description
Microsoft Management Console Remote Code Execution Vulnerability
Show more
Show less
Latest Patch info
Patch Name
secure@microsoft.com
Date
08.10.2024
Script

Script Type
Detection script
❗ CVE-2024-43572 is a vulnerability affecting Microsoft Management Console (MMC) when Author Mode is enabled. This vulnerability allows attackers to create malicious .msc (Microsoft Saved Console) files that execute arbitrary code on the target system. These files, when opened in Author Mode, can bypass security measures and execute unauthorized commands.
ℹ️ This detection script identifies potential risks by performing the following checks:
Search for Suspicious .msc Files:
Scans common directories (Documents, Downloads, Desktop, and Temp) for .msc files.
Filters for .msc files created within the last 7 days to identify potentially untrusted or malicious files.
Check MMC Author Mode Configuration:
Queries the registry path HKLM:\Software\Policies\Microsoft\MMC to check the RestrictAuthorMode value.
If RestrictAuthorMode is set to 0 or missing, Author Mode is enabled, leaving the system vulnerable.
If RestrictAuthorMode is set to any other value, Author Mode is disabled, mitigating the vulnerability.
Report Findings:
Outputs a list of detected untrusted .msc files, if any.
Reports whether Author Mode is enabled or disabled in MMC.
✅ By running this detection script, you can identify both potentially malicious .msc files and configuration weaknesses related to CVE-2024-43572.
Read more
Read less
Affected OS & Apps
Windows 11 24H2
by
Microsoft
Windows Server 2022 23H2
by
Microsoft
Windows 11 23H2
by
Microsoft
Show more
Patch faster and smarter
with vRx
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Trusted by 600+ customers:




Solution
Patch faster and better with vRx
Patch Management
vRx automatically deploys patches across all systems, cutting patching time by 80%.
Scripting Engine
vRx’s scripting engine solves complex vulnerabilities, like log4j, with built-in or custom scripts.
Patchless Protection
vRx’s Patchless Protection secures vulnerable apps and reduces risk while maintaining functionality.

Automated Patching, Scripting, and more
Talk with our team to get a personal walkthrough
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.