{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "nl",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions:\n\n    NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein.\n\n    NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory.\n    This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            },
            {
                "category": "description",
                "text": "Microsoft heeft kwetsbaarheden verholpen in Windows.",
                "title": "Feiten"
            },
            {
                "category": "description",
                "text": "Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:\n\n- Denial-of-Service (DoS)\n- Uitvoer van willekeurige code  (Gebruikersrechten)\n- Uitvoer van willekeurige code (Systeemrechten)\n- Verkrijgen van verhoogde rechten\n- Toegang tot gevoelige gegevens\n- Spoofing\n\nVan de kwetsbaarheden met kenmerk CVE-2024-43451 en CVE-2024-49019 geeft Microsoft aan signalen te hebben dat informatie gedeeld wordt in diverse groepen.\n\nVan de kwetsbaarheden met kenmerk CVE-2024-43451 en CVE-2024-49039 geeft Microsoft aan dat deze beperkt en gericht zijn misbruikt.\nDeze kwetsbaarheden bevinden zich respectievelijk in NTLMv2 en de task scheduler en stellen een kwaadwillende in staat zich voor te doen als een andere gebruiker met mogelijk hogere rechten.\nSuccesvol misbruik is niet eenvoudig en vereist dat de kwaadwillende het slachtoffer misleidt een malafide applicatie te draaien.\n\n```\nWindows Task Scheduler: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-49039 | 8.80 | Verkrijgen van verhoogde rechten    | \n|----------------|------|-------------------------------------|\n\nWindows Update Stack: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43530 | 7.80 | Verkrijgen van verhoogde rechten    | \n|----------------|------|-------------------------------------|\n\nWindows USB Video Driver: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43634 | 6.80 | Verkrijgen van verhoogde rechten    | \n| CVE-2024-43637 | 6.80 | Verkrijgen van verhoogde rechten    | \n| CVE-2024-43638 | 6.80 | Verkrijgen van verhoogde rechten    | \n| CVE-2024-43643 | 6.80 | Verkrijgen van verhoogde rechten    | \n| CVE-2024-43449 | 6.80 | Verkrijgen van verhoogde rechten    | \n|----------------|------|-------------------------------------|\n\nWindows Kernel: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43630 | 7.80 | Verkrijgen van verhoogde rechten    | \n|----------------|------|-------------------------------------|\n\nWindows Registry: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43452 | 7.50 | Verkrijgen van verhoogde rechten    | \n| CVE-2024-43641 | 7.80 | Verkrijgen van verhoogde rechten    | \n|----------------|------|-------------------------------------|\n\nMicrosoft Virtual Hard Drive: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-38264 | 5.90 | Denial-of-Service                   | \n|----------------|------|-------------------------------------|\n\nWindows Package Library Manager: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-38203 | 6.20 | Toegang tot gevoelige gegevens      | \n|----------------|------|-------------------------------------|\n\nRole: Windows Hyper-V: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43624 | 8.80 | Verkrijgen van verhoogde rechten    | \n| CVE-2024-43633 | 6.50 | Denial-of-Service                   | \n|----------------|------|-------------------------------------|\n\nWindows Defender Application Control (WDAC): \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43645 | 6.70 | Omzeilen van beveiligingsmaatregel  | \n|----------------|------|-------------------------------------|\n\nWindows SMBv3 Client/Server: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43447 | 8.10 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nWindows VMSwitch: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43625 | 8.10 | Verkrijgen van verhoogde rechten    | \n|----------------|------|-------------------------------------|\n\nWindows Win32 Kernel Subsystem: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-49046 | 7.80 | Verkrijgen van verhoogde rechten    | \n|----------------|------|-------------------------------------|\n\nWindows CSC Service: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43644 | 7.80 | Verkrijgen van verhoogde rechten    | \n|----------------|------|-------------------------------------|\n\nRole: Windows Active Directory Certificate Services: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-49019 | 7.80 | Verkrijgen van verhoogde rechten    | \n|----------------|------|-------------------------------------|\n\nWindows SMB: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43642 | 7.50 | Denial-of-Service                   | \n|----------------|------|-------------------------------------|\n\nWindows NTLM: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43451 | 6.50 | Voordoen als andere gebruiker       | \n|----------------|------|-------------------------------------|\n\nWindows NT OS Kernel: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43623 | 7.80 | Verkrijgen van verhoogde rechten    | \n|----------------|------|-------------------------------------|\n\nWindows DWM Core Library: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43629 | 7.80 | Verkrijgen van verhoogde rechten    | \n| CVE-2024-43636 | 7.80 | Verkrijgen van verhoogde rechten    | \n|----------------|------|-------------------------------------|\n\nMicrosoft Windows DNS: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43450 | 7.50 | Voordoen als andere gebruiker       | \n|----------------|------|-------------------------------------|\n\nWindows Telephony Service: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43626 | 7.80 | Verkrijgen van verhoogde rechten    | \n| CVE-2024-43627 | 8.80 | Uitvoeren van willekeurige code     | \n| CVE-2024-43628 | 8.80 | Uitvoeren van willekeurige code     | \n| CVE-2024-43620 | 8.80 | Uitvoeren van willekeurige code     | \n| CVE-2024-43621 | 8.80 | Uitvoeren van willekeurige code     | \n| CVE-2024-43622 | 8.80 | Uitvoeren van willekeurige code     | \n| CVE-2024-43635 | 8.80 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nWindows Kerberos: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43639 | 9.80 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nWindows Secure Kernel Mode: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43631 | 6.70 | Verkrijgen van verhoogde rechten    | \n| CVE-2024-43646 | 6.70 | Verkrijgen van verhoogde rechten    | \n| CVE-2024-43640 | 9.80 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n```",
                "title": "Interpretaties"
            },
            {
                "category": "description",
                "text": "Microsoft heeft updates beschikbaar gesteld waarmee de beschreven kwetsbaarheden worden verholpen. We raden u aan om deze updates te installeren. Meer informatie over de kwetsbaarheden, de installatie van de updates en eventuele work-arounds vindt u op:\n\nhttps://portal.msrc.microsoft.com/en-us/security-guidance",
                "title": "Oplossingen"
            },
            {
                "category": "general",
                "text": "medium",
                "title": "Kans"
            },
            {
                "category": "general",
                "text": "high",
                "title": "Schade"
            },
            {
                "category": "general",
                "text": "Weak Authentication",
                "title": "CWE-1390"
            },
            {
                "category": "general",
                "text": "Untrusted Pointer Dereference",
                "title": "CWE-822"
            },
            {
                "category": "general",
                "text": "Time-of-check Time-of-use (TOCTOU) Race Condition",
                "title": "CWE-367"
            },
            {
                "category": "general",
                "text": "Double Free",
                "title": "CWE-415"
            },
            {
                "category": "general",
                "text": "Integer Overflow or Wraparound",
                "title": "CWE-190"
            },
            {
                "category": "general",
                "text": "Out-of-bounds Read",
                "title": "CWE-125"
            },
            {
                "category": "general",
                "text": "Improper Access Control",
                "title": "CWE-284"
            },
            {
                "category": "general",
                "text": "Use After Free",
                "title": "CWE-416"
            },
            {
                "category": "general",
                "text": "Heap-based Buffer Overflow",
                "title": "CWE-122"
            },
            {
                "category": "general",
                "text": "Stack-based Buffer Overflow",
                "title": "CWE-121"
            },
            {
                "category": "general",
                "text": "External Control of File Name or Path",
                "title": "CWE-73"
            },
            {
                "category": "general",
                "text": "Improper Authentication",
                "title": "CWE-287"
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "Nationaal Cyber Security Centrum",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "Kwetsbaarheden verholpen in Microsoft Windows",
        "tracking": {
            "current_release_date": "2024-11-12T18:53:07.914094Z",
            "id": "NCSC-2024-0434",
            "initial_release_date": "2024-11-12T18:53:07.914094Z",
            "revision_history": [
                {
                    "date": "2024-11-12T18:53:07.914094Z",
                    "number": "0",
                    "summary": "Initiele versie"
                }
            ],
            "status": "final",
            "version": "1.0.0"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "category": "product_name",
                        "name": "windows_10_1507",
                        "product": {
                            "name": "windows_10_1507",
                            "product_id": "CSAFPID-1713453",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.20826:*:*:*:*:*:x64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_10_1507",
                        "product": {
                            "name": "windows_10_1507",
                            "product_id": "CSAFPID-1713452",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.20826:*:*:*:*:*:x86:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_10_1607",
                        "product": {
                            "name": "windows_10_1607",
                            "product_id": "CSAFPID-1713455",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.7515:*:*:*:*:*:x64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_10_1607",
                        "product": {
                            "name": "windows_10_1607",
                            "product_id": "CSAFPID-1713454",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.7515:*:*:*:*:*:x86:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_10_1809",
                        "product": {
                            "name": "windows_10_1809",
                            "product_id": "CSAFPID-1713436",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.6532:*:*:*:*:*:x64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_10_1809",
                        "product": {
                            "name": "windows_10_1809",
                            "product_id": "CSAFPID-1713435",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.6532:*:*:*:*:*:x86:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_10_21h2",
                        "product": {
                            "name": "windows_10_21h2",
                            "product_id": "CSAFPID-1713440",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.5131:*:*:*:*:*:arm64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_10_21h2",
                        "product": {
                            "name": "windows_10_21h2",
                            "product_id": "CSAFPID-1713441",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.5131:*:*:*:*:*:x64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_10_21h2",
                        "product": {
                            "name": "windows_10_21h2",
                            "product_id": "CSAFPID-1713439",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.5131:*:*:*:*:*:x86:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_10_22h2",
                        "product": {
                            "name": "windows_10_22h2",
                            "product_id": "CSAFPID-1713445",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_10_22h2:10.0.19044.5131:*:*:*:*:*:arm64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_10_22h2",
                        "product": {
                            "name": "windows_10_22h2",
                            "product_id": "CSAFPID-1713444",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5131:*:*:*:*:*:x64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_10_22h2",
                        "product": {
                            "name": "windows_10_22h2",
                            "product_id": "CSAFPID-1713446",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5131:*:*:*:*:*:x86:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_11_22h2",
                        "product": {
                            "name": "windows_11_22h2",
                            "product_id": "CSAFPID-1713442",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_11_22h2:10.0.22621.4460:*:*:*:*:*:arm64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_11_22h2",
                        "product": {
                            "name": "windows_11_22h2",
                            "product_id": "CSAFPID-1713443",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_11_22h2:10.0.22621.4460:*:*:*:*:*:x64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_11_23h2",
                        "product": {
                            "name": "windows_11_23h2",
                            "product_id": "CSAFPID-1713447",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_11_23h2:10.0.22631.4460:*:*:*:*:*:arm64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_11_23h2",
                        "product": {
                            "name": "windows_11_23h2",
                            "product_id": "CSAFPID-1713448",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_11_23h2:10.0.22631.4460:*:*:*:*:*:x64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_11_24h2",
                        "product": {
                            "name": "windows_11_24h2",
                            "product_id": "CSAFPID-1713492",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_11_24h2:10.0.26100.2314:*:*:*:*:*:arm64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_11_24h2",
                        "product": {
                            "name": "windows_11_24h2",
                            "product_id": "CSAFPID-1713493",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_11_24h2:10.0.26100.2314:*:*:*:*:*:x64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_server_2008_r2",
                        "product": {
                            "name": "windows_server_2008_r2",
                            "product_id": "CSAFPID-1713489",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_server_2008_r2:6.1.7601.27415:*:*:*:*:*:x64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_server_2008_sp2",
                        "product": {
                            "name": "windows_server_2008_sp2",
                            "product_id": "CSAFPID-1713490",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_server_2008_sp2:6.0.6003.22966:*:*:*:*:*:x64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_server_2008_sp2",
                        "product": {
                            "name": "windows_server_2008_sp2",
                            "product_id": "CSAFPID-1713491",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_server_2008_sp2:6.0.6003.22966:*:*:*:*:*:x86:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_server_2012",
                        "product": {
                            "name": "windows_server_2012",
                            "product_id": "CSAFPID-1713488",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_server_2012:6.2.9200.25165:*:*:*:*:*:x64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_server_2012_r2",
                        "product": {
                            "name": "windows_server_2012_r2",
                            "product_id": "CSAFPID-1713494",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_server_2012_r2:6.3.9600.22267:*:*:*:*:*:x64:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_server_2016",
                        "product": {
                            "name": "windows_server_2016",
                            "product_id": "CSAFPID-1713456",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_server_2016:10.0.14393.7515:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_server_2019",
                        "product": {
                            "name": "windows_server_2019",
                            "product_id": "CSAFPID-1713437",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.6532:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_server_2022",
                        "product": {
                            "name": "windows_server_2022",
                            "product_id": "CSAFPID-1713438",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.2849:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "windows_server_23h2",
                        "product": {
                            "name": "windows_server_23h2",
                            "product_id": "CSAFPID-1713449",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:o:microsoft:windows_server_23h2:10.0.25398.1251:*:*:*:*:*:*:*"
                            }
                        }
                    }
                ],
                "category": "vendor",
                "name": "microsoft"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2024-43530",
            "cwe": {
                "id": "CWE-284",
                "name": "Improper Access Control"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Access Control",
                    "title": "CWE-284"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43530",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43530.json"
                }
            ],
            "title": "CVE-2024-43530"
        },
        {
            "cve": "CVE-2024-43623",
            "cwe": {
                "id": "CWE-190",
                "name": "Integer Overflow or Wraparound"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Integer Overflow or Wraparound",
                    "title": "CWE-190"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43623",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43623.json"
                }
            ],
            "title": "CVE-2024-43623"
        },
        {
            "cve": "CVE-2024-43625",
            "cwe": {
                "id": "CWE-416",
                "name": "Use After Free"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Use After Free",
                    "title": "CWE-416"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43625",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43625.json"
                }
            ],
            "title": "CVE-2024-43625"
        },
        {
            "cve": "CVE-2024-43626",
            "cwe": {
                "id": "CWE-122",
                "name": "Heap-based Buffer Overflow"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Heap-based Buffer Overflow",
                    "title": "CWE-122"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43626",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43626.json"
                }
            ],
            "title": "CVE-2024-43626"
        },
        {
            "cve": "CVE-2024-43627",
            "cwe": {
                "id": "CWE-122",
                "name": "Heap-based Buffer Overflow"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Heap-based Buffer Overflow",
                    "title": "CWE-122"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43627",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43627.json"
                }
            ],
            "title": "CVE-2024-43627"
        },
        {
            "cve": "CVE-2024-43628",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43628",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43628.json"
                }
            ],
            "title": "CVE-2024-43628"
        },
        {
            "cve": "CVE-2024-43630",
            "cwe": {
                "id": "CWE-121",
                "name": "Stack-based Buffer Overflow"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Stack-based Buffer Overflow",
                    "title": "CWE-121"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43630",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43630.json"
                }
            ],
            "title": "CVE-2024-43630"
        },
        {
            "cve": "CVE-2024-43631",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43631",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43631.json"
                }
            ],
            "title": "CVE-2024-43631"
        },
        {
            "cve": "CVE-2024-43634",
            "cwe": {
                "id": "CWE-125",
                "name": "Out-of-bounds Read"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Out-of-bounds Read",
                    "title": "CWE-125"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43634",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43634.json"
                }
            ],
            "title": "CVE-2024-43634"
        },
        {
            "cve": "CVE-2024-43637",
            "cwe": {
                "id": "CWE-125",
                "name": "Out-of-bounds Read"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Out-of-bounds Read",
                    "title": "CWE-125"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43637",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43637.json"
                }
            ],
            "title": "CVE-2024-43637"
        },
        {
            "cve": "CVE-2024-43638",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43638",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43638.json"
                }
            ],
            "title": "CVE-2024-43638"
        },
        {
            "cve": "CVE-2024-43643",
            "cwe": {
                "id": "CWE-125",
                "name": "Out-of-bounds Read"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Out-of-bounds Read",
                    "title": "CWE-125"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43643",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43643.json"
                }
            ],
            "title": "CVE-2024-43643"
        },
        {
            "cve": "CVE-2024-43644",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43644",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43644.json"
                }
            ],
            "title": "CVE-2024-43644"
        },
        {
            "cve": "CVE-2024-43646",
            "cwe": {
                "id": "CWE-822",
                "name": "Untrusted Pointer Dereference"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Untrusted Pointer Dereference",
                    "title": "CWE-822"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43646",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43646.json"
                }
            ],
            "title": "CVE-2024-43646"
        },
        {
            "cve": "CVE-2024-43447",
            "cwe": {
                "id": "CWE-415",
                "name": "Double Free"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Double Free",
                    "title": "CWE-415"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43447",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43447.json"
                }
            ],
            "title": "CVE-2024-43447"
        },
        {
            "cve": "CVE-2024-43449",
            "cwe": {
                "id": "CWE-125",
                "name": "Out-of-bounds Read"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Out-of-bounds Read",
                    "title": "CWE-125"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43449",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43449.json"
                }
            ],
            "title": "CVE-2024-43449"
        },
        {
            "cve": "CVE-2024-43450",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43450",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43450.json"
                }
            ],
            "title": "CVE-2024-43450"
        },
        {
            "cve": "CVE-2024-43451",
            "cwe": {
                "id": "CWE-73",
                "name": "External Control of File Name or Path"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "External Control of File Name or Path",
                    "title": "CWE-73"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43451",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43451.json"
                }
            ],
            "title": "CVE-2024-43451"
        },
        {
            "cve": "CVE-2024-43452",
            "cwe": {
                "id": "CWE-367",
                "name": "Time-of-check Time-of-use (TOCTOU) Race Condition"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Time-of-check Time-of-use (TOCTOU) Race Condition",
                    "title": "CWE-367"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43452",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43452.json"
                }
            ],
            "title": "CVE-2024-43452"
        },
        {
            "cve": "CVE-2024-49046",
            "cwe": {
                "id": "CWE-367",
                "name": "Time-of-check Time-of-use (TOCTOU) Race Condition"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Time-of-check Time-of-use (TOCTOU) Race Condition",
                    "title": "CWE-367"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1713435",
                    "CSAFPID-1713436",
                    "CSAFPID-1713437",
                    "CSAFPID-1713438",
                    "CSAFPID-1713439",
                    "CSAFPID-1713440",
                    "CSAFPID-1713441",
                    "CSAFPID-1713442",
                    "CSAFPID-1713443",
                    "CSAFPID-1713444",
                    "CSAFPID-1713445",
                    "CSAFPID-1713446",
                    "CSAFPID-1713447",
                    "CSAFPID-1713448",
                    "CSAFPID-1713449",
                    "CSAFPID-1713492",
                    "CSAFPID-1713493",
                    "CSAFPID-1713452",
                    "CSAFPID-1713453",
                    "CSAFPID-1713454",
                    "CSAFPID-1713455",
                    "CSAFPID-1713456",
                    "CSAFPID-1713490",
                    "CSAFPID-1713491",
                    "CSAFPID-1713489",
                    "CSAFPID-1713488",
                    "CSAFPID-1713494"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-49046",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-49046.json"
                }
            ],
            "title": "CVE-2024-49046"
        },
        {
            "cve": "CVE-2024-43620",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43620",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43620.json"
                }
            ],
            "title": "CVE-2024-43620"
        },
        {
            "cve": "CVE-2024-43621",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43621",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43621.json"
                }
            ],
            "title": "CVE-2024-43621"
        },
        {
            "cve": "CVE-2024-43622",
            "cwe": {
                "id": "CWE-122",
                "name": "Heap-based Buffer Overflow"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Heap-based Buffer Overflow",
                    "title": "CWE-122"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43622",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43622.json"
                }
            ],
            "title": "CVE-2024-43622"
        },
        {
            "cve": "CVE-2024-43624",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43624",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43624.json"
                }
            ],
            "title": "CVE-2024-43624"
        },
        {
            "cve": "CVE-2024-43629",
            "cwe": {
                "id": "CWE-822",
                "name": "Untrusted Pointer Dereference"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Untrusted Pointer Dereference",
                    "title": "CWE-822"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43629",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43629.json"
                }
            ],
            "title": "CVE-2024-43629"
        },
        {
            "cve": "CVE-2024-43635",
            "cwe": {
                "id": "CWE-190",
                "name": "Integer Overflow or Wraparound"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Integer Overflow or Wraparound",
                    "title": "CWE-190"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1713435",
                    "CSAFPID-1713436",
                    "CSAFPID-1713488",
                    "CSAFPID-1713437",
                    "CSAFPID-1713489",
                    "CSAFPID-1713444",
                    "CSAFPID-1713490",
                    "CSAFPID-1713445",
                    "CSAFPID-1713443",
                    "CSAFPID-1713491",
                    "CSAFPID-1713442",
                    "CSAFPID-1713449",
                    "CSAFPID-1713453",
                    "CSAFPID-1713439",
                    "CSAFPID-1713454",
                    "CSAFPID-1713456",
                    "CSAFPID-1713448",
                    "CSAFPID-1713440",
                    "CSAFPID-1713492",
                    "CSAFPID-1713455",
                    "CSAFPID-1713493",
                    "CSAFPID-1713452",
                    "CSAFPID-1713438",
                    "CSAFPID-1713446",
                    "CSAFPID-1713447",
                    "CSAFPID-1713494",
                    "CSAFPID-1713441"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43635",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43635.json"
                }
            ],
            "title": "CVE-2024-43635"
        },
        {
            "cve": "CVE-2024-43636",
            "cwe": {
                "id": "CWE-822",
                "name": "Untrusted Pointer Dereference"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Untrusted Pointer Dereference",
                    "title": "CWE-822"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43636",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43636.json"
                }
            ],
            "title": "CVE-2024-43636"
        },
        {
            "cve": "CVE-2024-43639",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43639",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43639.json"
                }
            ],
            "title": "CVE-2024-43639"
        },
        {
            "cve": "CVE-2024-43640",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43640",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43640.json"
                }
            ],
            "title": "CVE-2024-43640"
        },
        {
            "cve": "CVE-2024-43641",
            "cwe": {
                "id": "CWE-190",
                "name": "Integer Overflow or Wraparound"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Integer Overflow or Wraparound",
                    "title": "CWE-190"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43641",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43641.json"
                }
            ],
            "title": "CVE-2024-43641"
        },
        {
            "cve": "CVE-2024-43642",
            "cwe": {
                "id": "CWE-416",
                "name": "Use After Free"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Use After Free",
                    "title": "CWE-416"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43642",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43642.json"
                }
            ],
            "title": "CVE-2024-43642"
        },
        {
            "cve": "CVE-2024-38203",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-38203",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-38203.json"
                }
            ],
            "title": "CVE-2024-38203"
        },
        {
            "cve": "CVE-2024-49019",
            "cwe": {
                "id": "CWE-1390",
                "name": "Weak Authentication"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Weak Authentication",
                    "title": "CWE-1390"
                }
            ],
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-49019",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-49019.json"
                }
            ],
            "title": "CVE-2024-49019"
        },
        {
            "cve": "CVE-2024-49039",
            "cwe": {
                "id": "CWE-287",
                "name": "Improper Authentication"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Authentication",
                    "title": "CWE-287"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1713435",
                    "CSAFPID-1713436",
                    "CSAFPID-1713437",
                    "CSAFPID-1713438",
                    "CSAFPID-1713439",
                    "CSAFPID-1713440",
                    "CSAFPID-1713441",
                    "CSAFPID-1713442",
                    "CSAFPID-1713443",
                    "CSAFPID-1713444",
                    "CSAFPID-1713445",
                    "CSAFPID-1713446",
                    "CSAFPID-1713447",
                    "CSAFPID-1713448",
                    "CSAFPID-1713449",
                    "CSAFPID-1713492",
                    "CSAFPID-1713493",
                    "CSAFPID-1713452",
                    "CSAFPID-1713453",
                    "CSAFPID-1713454",
                    "CSAFPID-1713455",
                    "CSAFPID-1713456"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-49039",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-49039.json"
                }
            ],
            "title": "CVE-2024-49039"
        },
        {
            "cve": "CVE-2024-38264",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-38264",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-38264.json"
                }
            ],
            "title": "CVE-2024-38264"
        },
        {
            "cve": "CVE-2024-43633",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43633",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43633.json"
                }
            ],
            "title": "CVE-2024-43633"
        },
        {
            "cve": "CVE-2024-43645",
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43645",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43645.json"
                }
            ],
            "title": "CVE-2024-43645"
        }
    ]
}