CVE-2024-43491: CWE-416: Use After Free in Microsoft Windows 10 Version 1507
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.
AI Analysis
Technical Summary
Microsoft identified a use-after-free vulnerability (CWE-416) in the Servicing Stack of Windows 10 Version 1507 (build 10240.0), specifically impacting the Enterprise 2015 LTSB and IoT Enterprise 2015 LTSB editions. The issue arose because recent updates, including KB5035858 released March 12, 2024, rolled back previous fixes for vulnerabilities in Optional Components, effectively re-exposing these flaws. This vulnerability has a CVSS 3.1 score of 9.8 (critical) with network attack vector, no privileges required, no user interaction, and complete confidentiality, integrity, and availability impact. Microsoft’s advisory states that the vulnerability is addressed by applying the September 2024 Servicing Stack Update (KB5043936) followed by the September 2024 security update (KB5043083). Other Windows 10 versions are not affected. The vulnerability is officially fixed and no known exploits are reported in the wild.
Potential Impact
An attacker could exploit this use-after-free vulnerability to execute arbitrary code remotely without requiring privileges or user interaction, potentially leading to full system compromise including complete confidentiality, integrity, and availability loss on affected Windows 10 Version 1507 systems. The vulnerability affects only the Enterprise 2015 LTSB and IoT Enterprise 2015 LTSB editions with specific updates installed. Other Windows 10 versions are not impacted.
Mitigation Recommendations
Microsoft has released an official fix for this vulnerability. To remediate, install the September 2024 Servicing Stack Update (KB5043936) first, followed by the September 2024 Windows security update (KB5043083). Systems running Windows 10 Version 1507 Enterprise 2015 LTSB and IoT Enterprise 2015 LTSB editions should apply these updates promptly. No other mitigation is required as the vulnerability is addressed by these official patches.
CVE-2024-43491: CWE-416: Use After Free in Microsoft Windows 10 Version 1507
Description
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.
CVSS v3.1
Score 9.8critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Microsoft identified a use-after-free vulnerability (CWE-416) in the Servicing Stack of Windows 10 Version 1507 (build 10240.0), specifically impacting the Enterprise 2015 LTSB and IoT Enterprise 2015 LTSB editions. The issue arose because recent updates, including KB5035858 released March 12, 2024, rolled back previous fixes for vulnerabilities in Optional Components, effectively re-exposing these flaws. This vulnerability has a CVSS 3.1 score of 9.8 (critical) with network attack vector, no privileges required, no user interaction, and complete confidentiality, integrity, and availability impact. Microsoft’s advisory states that the vulnerability is addressed by applying the September 2024 Servicing Stack Update (KB5043936) followed by the September 2024 security update (KB5043083). Other Windows 10 versions are not affected. The vulnerability is officially fixed and no known exploits are reported in the wild.
Potential Impact
An attacker could exploit this use-after-free vulnerability to execute arbitrary code remotely without requiring privileges or user interaction, potentially leading to full system compromise including complete confidentiality, integrity, and availability loss on affected Windows 10 Version 1507 systems. The vulnerability affects only the Enterprise 2015 LTSB and IoT Enterprise 2015 LTSB editions with specific updates installed. Other Windows 10 versions are not impacted.
Mitigation Recommendations
Microsoft has released an official fix for this vulnerability. To remediate, install the September 2024 Servicing Stack Update (KB5043936) first, followed by the September 2024 Windows security update (KB5043083). Systems running Windows 10 Version 1507 Enterprise 2015 LTSB and IoT Enterprise 2015 LTSB editions should apply these updates promptly. No other mitigation is required as the vulnerability is addressed by these official patches.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- microsoft
- Date Reserved
- 2024-08-14T01:08:33.521Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- official-fix
- Vendor Advisory Urls
- [{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43491","vendor":"Microsoft"}]
Threat ID: 699f6cdab7ef31ef0b56989d
Added to database: 02/25/2026, 21:42:50 UTC
Last enriched: 08/11/2026, 15:58:41 UTC
Last updated: 09/10/2026, 19:36:48 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.