CVE-2024-43491
A permanent, source-backed tracker page. Values are shown only when returned; explicit gaps and read failures remain different states.
What it is
ReportedMicrosoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024.… Source description excerpt; complete tracked detail loads below.
NVD published: Sep 10, 2024 · Source record updated: Aug 9, 2026 · Tracker snapshot: Aug 9, 2026
What is affected
ReportedMicrosoft — Windows. Product-level identification only; no affected-version conclusion is available from this field.
NVD published: Sep 10, 2024 · Source record updated: Aug 9, 2026 · Tracker snapshot: Aug 9, 2026
Urgency and basis
ReportedAct now · 557.5
Tracker decision tier from the evidence detailed below · Source record updated: Aug 9, 2026 · Tracker snapshot: Aug 9, 2026
Exploitation evidence
Reportedkev-listed · VulnCheck KEV
VulnCheck KEV added: Sep 10, 2024 · Source record updated: Aug 9, 2026 · Tracker snapshot: Aug 9, 2026
What to do
ReportedApply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Source remediation ↗Tracked source remediation field · Source record updated: Aug 9, 2026 · Tracker snapshot: Aug 9, 2026
Evidence detail
Loading the full tracker evidence record…