# Microsoft CVEs of 2024 With a High EPSS

CVEs of Microsoft products published in 2024 whose EPSS score is 0.5 or more.

Source: https://docs.deepinfo.com/reference/vulnerability/search/examples/microsoft-2024-high-epss/

Last updated: 2026-09-26

---
`POST https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25`

CVEs of Microsoft products published in 2024 whose EPSS score is 0.5 or more.

Example 3 of 6 in **Combinations** · [Vulnerability Search Examples](/reference/vulnerability/search/examples/) · endpoint: [Search](/reference/vulnerability/search/)

Tags: `field` `enrichment.cpe.vendor` · `field` `published` · `field` `enrichment.epss_score.epss` · `operator` `eq` · `operator` `gte` · `operator` `lte`

A vendor, a date range and a score threshold together.

In the response, look at `results[].published` and `results[].enrichment.epss_score.epss`.

## Request

| Parameter | In | Value |
|---|---|---|
| `page_size` | query | `25` |
| `filters.must[0].name` | body | `enrichment.cpe.vendor` |
| `filters.must[0].type` | body | `eq` |
| `filters.must[0].value` | body | `microsoft` |
| `filters.must[1].name` | body | `published` |
| `filters.must[1].type` | body | `gte` |
| `filters.must[1].value` | body | `2024-01-01T00:00:00Z` |
| `filters.must[2].name` | body | `published` |
| `filters.must[2].type` | body | `lte` |
| `filters.must[2].value` | body | `2024-12-31T23:59:59Z` |
| `filters.must[3].name` | body | `enrichment.epss_score.epss` |
| `filters.must[3].type` | body | `gte` |
| `filters.must[3].value` | body | `0.5` |

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "enrichment.cpe.vendor",
        "type": "eq",
        "value": "microsoft"
      },
      {
        "name": "published",
        "type": "gte",
        "value": "2024-01-01T00:00:00Z"
      },
      {
        "name": "published",
        "type": "lte",
        "value": "2024-12-31T23:59:59Z"
      },
      {
        "name": "enrichment.epss_score.epss",
        "type": "gte",
        "value": 0.5
      }
    ]
  }
}'
```

## Response

### 200 · OK

> Shortened for this page: results: 3 of 25 shown; results[].configurations[].nodes[].cpe_match: first 10 items; results[].enrichment.cpe: first 10 items; results[].references: first 10 items

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `x-ratelimit-limit-second: 1` · `x-ratelimit-remaining-second: 0` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 28,
  "results": [
    {
      "id": "CVE-2024-49112",
      "source_identifier": "user@microsoft.com",
      "published": "2024-12-12T02:04:37Z",
      "last_modified": "2026-06-17T07:59:25Z",
      "status": "Analyzed",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability"
        },
        {
          "lang": "es",
          "value": "Vulnerabilidad de ejecución remota de código en el Protocolo ligero de acceso a directorios (LDAP) de Windows"
        }
      ],
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49112",
          "source": "user@microsoft.com",
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@microsoft.com",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "UNCHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 9.8,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 5.9
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@microsoft.com",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-190"
            }
          ]
        },
        {
          "source": "user@nist.gov",
          "type": "Primary",
          "description": [
            {
              "lang": "en",
              "value": "NVD-CWE-noinfo"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
                  "match_criteria_id": "10F567C3-3739-4F3D-B9E0-D2725D09CE0D",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "10.0.10240.20857"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
                  "match_criteria_id": "04D1F48B-C323-4062-B5E1-9700ADBB153C",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "10.0.10240.20857"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
                  "match_criteria_id": "29B44B5E-3D35-4A5B-A916-6E70923FAB7C",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "10.0.14393.7606"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                  "match_criteria_id": "77EAFFB9-3053-4197-B52D-69F4F86C8FBA",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "10.0.14393.7606"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                  "match_criteria_id": "5FA7C375-3A7C-4F34-B6E7-82C187B4F7AF",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "10.0.17763.6659"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                  "match_criteria_id": "576F141F-C874-4817-961A-2C4D2AB3DEA4",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "10.0.17763.6659"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "F814C24B-FA54-4B97-8387-6EE9AC269178",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "10.0.19044.5247"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "6CF40E59-FC32-4047-8A63-EE0819A32962",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "10.0.19045.5247"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "0C3B0836-B782-4C1A-B0D1-B6111CBC8DED",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "10.0.22621.4602"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "594D3E33-9ADE-47EF-8032-A5EDC948F92B",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "10.0.26100.2605"
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
            "vendor": "microsoft",
            "product": "windows_10_1507",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "10.0.10240.20857",
            "affected_versions_first": "10.0.10240.16405",
            "affected_versions_last": "10.0.10240.20826"
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
            "vendor": "microsoft",
            "product": "windows_10_1507",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "10.0.10240.20857",
            "affected_versions_first": "10.0.10240.16405",
            "affected_versions_last": "10.0.10240.20826"
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
            "vendor": "microsoft",
            "product": "windows_10_1607",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "10.0.14393.7606",
            "affected_versions_first": "10.0.10240.20915",
            "affected_versions_last": "10.0.14393.7515"
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
            "vendor": "microsoft",
            "product": "windows_10_1607",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "10.0.14393.7606",
            "affected_versions_first": "10.0.10240.20915",
            "affected_versions_last": "10.0.14393.7515"
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
            "vendor": "microsoft",
            "product": "windows_10_1809",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "10.0.17763.6659",
            "affected_versions_first": "10.0.17763.1",
            "affected_versions_last": "10.0.17763.6532"
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
            "vendor": "microsoft",
            "product": "windows_10_1809",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "10.0.17763.6659",
            "affected_versions_first": "10.0.17763.1",
            "affected_versions_last": "10.0.17763.6532"
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
            "vendor": "microsoft",
            "product": "windows_10_21h2",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "10.0.19044.5247",
            "affected_versions_first": "10.0.14393.5989",
            "affected_versions_last": "10.0.19044.5131"
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
            "vendor": "microsoft",
            "product": "windows_10_22h2",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "10.0.19045.5247",
            "affected_versions_first": "10.0.19041.3570",
            "affected_versions_last": "10.0.19045.5131"
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*",
            "vendor": "microsoft",
            "product": "windows_11_22h2",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "10.0.22621.4602",
            "affected_versions_first": "10.0.22000.1413",
            "affected_versions_last": "10.0.22621.4541"
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
            "vendor": "microsoft",
            "product": "windows_11_24h2",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "10.0.26100.2605",
            "affected_versions_first": "10.0.26100.1742",
            "affected_versions_last": "10.0.26100.2454"
          }
        ],
        "cwe": [
          {
            "id": 190,
            "owasptop10_2021": null,
            "name": "Integer Overflow or Wraparound",
            "description": "The product performs a calculation that can\n         produce an integer overflow or wraparound when the logic\n         assumes that the resulting value will always be larger than\n         the original value. This occurs when an integer value is\n         incremented to a value that is too large to store in the\n         associated representation. When this occurs, the value may\n         become a very small or negative number.",
            "capec_id": [
              92
            ],
            "scope": [
              "Access Control",
              "Availability",
              "Confidentiality",
              "Integrity",
              "Other"
            ],
            "impact": [
              "Alter Execution Logic",
              "Bypass Protection Mechanism",
              "DoS: Crash, Exit, or Restart",
              "DoS: Instability",
              "DoS: Resource Consumption (CPU)",
              "DoS: Resource Consumption (Memory)",
              "Execute Unauthorized Code or Commands",
              "Modify Memory"
            ],
            "detection_method": [
              "Architecture or Design Review",
              "Automated Static Analysis",
              "Automated Static Analysis - Binary or Bytecode",
              "Automated Static Analysis - Source Code",
              "Black Box",
              "Dynamic Analysis with Manual Results Interpretation",
              "Manual Analysis",
              "Manual Static Analysis - Source Code"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.71877,
          "percentile": 0.994,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "user@microsoft.com",
          "type": "Secondary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 9.8,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2024-4577",
      "source_identifier": "user@php.net",
      "published": "2024-06-09T20:15:09Z",
      "last_modified": "2026-06-17T08:02:11Z",
      "status": "Analyzed",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": "2024-06-12",
      "cisa_action_due": "2024-07-03",
      "cisa_required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
      "cisa_vulnerability_name": "PHP-CGI OS Command Injection Vulnerability",
      "descriptions": [
        {
          "lang": "en",
          "value": "In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use \"Best-Fit\" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc."
        },
        {
          "lang": "es",
          "value": "En las versiones de PHP 8.1.* anteriores a 8.1.29, 8.2.* anteriores a 8.2.20, 8.3.* anteriores a 8.3.8, cuando se usa Apache y PHP-CGI en Windows, si el sistema está configurado para usar ciertas páginas de códigos, Windows puede utilizar el comportamiento \"Mejor ajuste\" para reemplazar caracteres en la línea de comando proporcionada a las funciones de la API de Win32. El módulo PHP CGI puede malinterpretar esos caracteres como opciones de PHP, lo que puede permitir a un usuario malintencionado pasar opciones al binario PHP que se está ejecutando y, por lo tanto, revelar el código fuente de los scripts, ejecutar código PHP arbitrario en el servidor, etc."
        }
      ],
      "references": [
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/06/07/1",
          "source": "user@php.net",
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://arstechnica.com/security/2024/06/php-vulnerability-allows-attackers-to-run-malicious-code-on-windows-servers/",
          "source": "user@php.net",
          "tags": [
            "Exploit",
            "Press/Media Coverage",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html",
          "source": "user@php.net",
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://cert.be/en/advisory/warning-php-remote-code-execution-patch-immediately",
          "source": "user@php.net",
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability-en/",
          "source": "user@php.net",
          "tags": [
            "Exploit",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/11whoami99/CVE-2024-4577",
          "source": "user@php.net",
          "tags": [
            "Exploit"
          ]
        },
        {
          "url": "https://github.com/php/php-src/security/advisories/GHSA-3qgc-jrrr-25jv",
          "source": "user@php.net",
          "tags": [
            "Exploit",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/rapid7/metasploit-framework/pull/19247",
          "source": "user@php.net",
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Patch"
          ]
        },
        {
          "url": "https://github.com/watchtowrlabs/CVE-2024-4577",
          "source": "user@php.net",
          "tags": [
            "Exploit",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/xcanwin/CVE-2024-4577-PHP-RCE",
          "source": "user@php.net",
          "tags": [
            "Exploit",
            "Third Party Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@php.net",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "UNCHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 9.8,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 5.9
          },
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "UNCHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 9.8,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 5.9
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@php.net",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-78"
            }
          ]
        },
        {
          "source": "user@nist.gov",
          "type": "Primary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-78"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "7DC2EEF8-834B-42A1-8DA3-0C2CF22A7070",
                  "version_start_including": "8.1.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "8.1.29"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "A39988FF-D854-4277-9D66-6911AF371DD3",
                  "version_start_including": "8.2.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "8.2.20"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "F579FFC1-4F81-4755-B14B-3AA73AC9FF7A",
                  "version_start_including": "8.3.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "8.3.8"
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*",
                  "match_criteria_id": "B8EDB836-4E6A-4B71-B9B2-AA3E03E0F646",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*",
                  "match_criteria_id": "CA277A6C-83EC-4536-9125-97B84C4FAF59",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
            "vendor": "php",
            "product": "php",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "8.1.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "8.1.29",
            "affected_versions_first": "8.1.0",
            "affected_versions_last": "8.1.28"
          },
          {
            "criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
            "vendor": "php",
            "product": "php",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "8.2.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "8.2.20",
            "affected_versions_first": "8.2.0",
            "affected_versions_last": "8.2.19"
          },
          {
            "criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
            "vendor": "php",
            "product": "php",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "8.3.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "8.3.8",
            "affected_versions_first": "8.3.0",
            "affected_versions_last": "8.3.7"
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
            "vendor": "microsoft",
            "product": "windows",
            "product_type": "o",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*",
            "vendor": "fedoraproject",
            "product": "fedora",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "39",
            "affected_versions_last": "39"
          },
          {
            "criteria": "cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*",
            "vendor": "fedoraproject",
            "product": "fedora",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "40",
            "affected_versions_last": "40"
          }
        ],
        "cwe": [
          {
            "id": 78,
            "owasptop10_2021": "A03 Injection",
            "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
            "description": "The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.",
            "capec_id": [
              6,
              15,
              43,
              88,
              108
            ],
            "scope": [
              "Availability",
              "Confidentiality",
              "Integrity",
              "Non-Repudiation"
            ],
            "impact": [
              "DoS: Crash, Exit, or Restart",
              "Execute Unauthorized Code or Commands",
              "Hide Activities",
              "Modify Application Data",
              "Modify Files or Directories",
              "Read Application Data",
              "Read Files or Directories"
            ],
            "detection_method": [
              "Architecture or Design Review",
              "Automated Dynamic Analysis",
              "Automated Static Analysis",
              "Automated Static Analysis - Binary or Bytecode",
              "Automated Static Analysis - Source Code",
              "Dynamic Analysis with Automated Results Interpretation",
              "Dynamic Analysis with Manual Results Interpretation",
              "Manual Static Analysis",
              "Manual Static Analysis - Source Code"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.99987,
          "percentile": 0.99983,
          "date": "2026-09-23"
        },
        "cisa_kev": {
          "vendor_project": "PHP Group",
          "product": "PHP",
          "vulnerability_name": "PHP-CGI OS Command Injection Vulnerability",
          "date_added": "2024-06-12",
          "short_description": "PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.",
          "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
          "due_date": "2024-07-03",
          "known_ransomware_campaign_use": "Known",
          "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see:  https://www.php.net/ChangeLog-8.php#;   https://nvd.nist.gov/vuln/detail/CVE-2024-4577"
        },
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "user@nist.gov",
          "type": "Primary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 9.8,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2024-43468",
      "source_identifier": "user@microsoft.com",
      "published": "2024-10-08T18:15:09Z",
      "last_modified": "2026-06-17T07:51:06Z",
      "status": "Analyzed",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": "2026-02-12",
      "cisa_action_due": "2026-03-05",
      "cisa_required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
      "cisa_vulnerability_name": "Microsoft Configuration Manager SQL Injection Vulnerability",
      "descriptions": [
        {
          "lang": "en",
          "value": "Microsoft Configuration Manager Remote Code Execution Vulnerability"
        },
        {
          "lang": "es",
          "value": "Vulnerabilidad de ejecución remota de código en Microsoft Configuration Manager"
        }
      ],
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43468",
          "source": "user@microsoft.com",
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-43468",
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "tags": [
            "US Government Resource"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@microsoft.com",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "UNCHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 9.8,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 5.9
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@microsoft.com",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-89"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:microsoft:configuration_manager_2403:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "AA84B441-EDC4-4871-AB6D-CDD3C638F5D0",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:microsoft:configuration_manager_2409:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "3832F552-1DE3-49A3-8B2B-C75C0D404279",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:microsoft:configuration_manager_2503:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "F476484B-C570-4389-A9D1-B6AE2B1C11F9",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:microsoft:configuration_manager_2403:-:*:*:*:*:*:*:*",
            "vendor": "microsoft",
            "product": "configuration_manager_2403",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:a:microsoft:configuration_manager_2409:-:*:*:*:*:*:*:*",
            "vendor": "microsoft",
            "product": "configuration_manager_2409",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:a:microsoft:configuration_manager_2503:-:*:*:*:*:*:*:*",
            "vendor": "microsoft",
            "product": "configuration_manager_2503",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          }
        ],
        "cwe": [
          {
            "id": 89,
            "owasptop10_2021": "A03 Injection",
            "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
            "description": "The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.",
            "capec_id": [
              7,
              66,
              108,
              109,
              110,
              470
            ],
            "scope": [
              "Access Control",
              "Authentication",
              "Availability",
              "Confidentiality",
              "Integrity"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "Execute Unauthorized Code or Commands",
              "Gain Privileges or Assume Identity",
              "Modify Application Data",
              "Read Application Data"
            ],
            "detection_method": [
              "Architecture or Design Review",
              "Automated Dynamic Analysis",
              "Automated Static Analysis",
              "Automated Static Analysis - Binary or Bytecode",
              "Automated Static Analysis - Source Code",
              "Dynamic Analysis with Automated Results Interpretation",
              "Dynamic Analysis with Manual Results Interpretation",
              "Manual Analysis",
              "Manual Static Analysis - Source Code"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.82022,
          "percentile": 0.99637,
          "date": "2026-09-23"
        },
        "cisa_kev": {
          "vendor_project": "Microsoft",
          "product": "Configuration Manager",
          "vulnerability_name": "Microsoft Configuration Manager SQL Injection Vulnerability",
          "date_added": "2026-02-12",
          "short_description": "Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.",
          "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
          "due_date": "2026-03-05",
          "known_ransomware_campaign_use": "Unknown",
          "notes": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43468 ; https://nvd.nist.gov/vuln/detail/CVE-2024-43468"
        },
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "user@microsoft.com",
          "type": "Secondary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 9.8,
            "base_severity": "CRITICAL"
          }
        }
      }
    }
  ]
}
```

## Related Examples

- [CVEs Published in December 2021](/reference/vulnerability/search/examples/published/)
- [Exploited, Critical and Likely to Be Exploited Again](/reference/vulnerability/search/examples/kev-critical-high-epss/)
- [SQL Injection or OS Command Injection Since September 2026](/reference/vulnerability/search/examples/sqli-or-command-injection-recent/)
- [Sort by Vendor](/reference/vulnerability/search/examples/sort-enrichment-cpe-vendor/)
- [EPSS 0.9 and Up](/reference/vulnerability/search/examples/enrichment-epss-score-epss/)
- [Sort by EPSS: Most Likely to Be Exploited First](/reference/vulnerability/search/examples/sort-epss/)
