CRITICAL 9.1 Microsoft PoC

CVE-2024-45337

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

Microsoft Security Update 2024-Dec: Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

Affected Products

References

Published: 2024-12-10 · Source: Microsoft · Feed updated: 2026-09-28
This critical severity vulnerability with a CVSS score of 9.1 was published on 2024-12-10 via Microsoft. 🚨 A public proof-of-concept exploit is available on GitHub. Affected: cbl2 moby-engine 24.0.9-12 on CBL Mariner 2.0, cbl2 cert-manager 1.11.2-16 on CBL Mariner 2.0, cbl2 moby-compose 2.17.3-9 on CBL Mariner 2.0 and 5 more.

Risk Timeline

CVE Disclosed2024-12-10 · 657 days ago
Public PoC Exploit AvailableWeaponised proof-of-concept code is publicly accessible

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2025-6965Integer Truncation on SQLiteCRITICAL9.8
CVE-2025-38497usb: gadget: configfs: Fix OOB read on empty string writeCRITICAL9.8
CVE-2025-1744Out-of-bounds Write in radare2CRITICAL9.8
CVE-2026-3381Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure verCRITICAL9.8
CVE-2026-4176Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from CRITICAL9.8
CVE-2026-33937Handlebars.js has JavaScript Injection via AST Type ConfusionCRITICAL9.8
vulnfeed aggregates 13625 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.