A critical elevation of privilege (EoP) vulnerability, identified as CVE-2024-43532 , has been discovered in the Windows Remote Registry client . This vulnerability could potentially allow attackers to relay NTLM authentication and gain unauthorized access to Windows systems
See also: Windows 11 24H2 blocked on two ASUS models due to bugs

It has a high CVSS score of 8.8 and affects all unpatched versions of Windows. Akamai researcher Stiv Kupchik discovered the vulnerability, which exploits an alternative mechanism in the WinReg client implementation .
This mechanism uses outdated, insecure transport protocols whenSMB transport is not available. The Windows Remote Registry EoP flaw was responsibly disclosed in the Microsoft Security Resource Center in February 2024 and subsequently fixed as part of the October 2024 patch.
The vulnerability is in the BaseBindToMachine in advapi32.dll, a core Windows API component. When attempting to connect to a remote registry using a UNC path, the function may fall back to using insecure authentication methods if the initial SMB connection fails.
See also: ScarCruft spreads RokRAT malware via Windows Zero-Day
Specifically, the issue arises when:
- The connection falls back to alternative protocols such as TCP/IP.
- The RpcBindingSetAuthInfoA is called with an authentication level of RPC_C_AUTHN_LEVEL_CONNECT.
This insecure configuration allows attackers to intercept and relay the client's NTLM authentication credentials.

By exploiting the EoP vulnerability in the Windows Remote Registry, an attacker can:
- Intercept NTLM authentication attempt.
- Relay the credentials to Active Directory Certificate Services (ADCS).
- Request a user certificate for further authentication to the domain.
Stiv Kupchik said this chain of attacks potentially allows adversaries to escalate privileges and gain unauthorized access to sensitive systems in a Windows domain environment.
See also: Windows 10 ends, only one year of support remains
Relay attacks are a type of cybercrime where hackers intercept and manipulate communications between devices to gain unauthorized access. These attacks are particularly dangerous for systems that use wireless communications, such as keyless entry systems and RFID tags. To combat relay attacks, implementing strong encryption and authentication measures is crucial, as well as using physical barriers, such as signal blocking cases or metal enclosures, to limit the range of wireless communications.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
