CRITICAL 9.1 Microsoft PoC

CVE-2024-5535

OpenSSL: CVE-2024-5535 SSL_select_next_proto buffer overread

Microsoft Security Update 2024-Nov: OpenSSL: CVE-2024-5535 SSL_select_next_proto buffer overread

Affected Products

References

Published: 2024-11-12 · Source: Microsoft · Feed updated: 2026-10-05
This critical severity vulnerability with a CVSS score of 9.1 was published on 2024-11-12 via Microsoft. 🚨 A public proof-of-concept exploit is available on GitHub. EPSS score: 5.6% (top 7% of all CVEs by exploitation probability). Affected: Azure Linux 3.0 x64, CBL Mariner 2.0 ARM, CBL Mariner 2.0 x64 and 3 more.

Risk Timeline

CVE Disclosed2024-11-12 · 691 days ago
Public PoC Exploit AvailableWeaponised proof-of-concept code is publicly accessible

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2025-29813Azure DevOps Elevation of Privilege VulnerabilityCRITICAL10.0
CVE-2025-54914Azure Networking Elevation of Privilege VulnerabilityCRITICAL10.0
CVE-2026-32169Azure Cloud Shell Elevation of Privilege VulnerabilityCRITICAL10.0
CVE-2025-65037Azure Container Apps Remote Code Execution VulnerabilityCRITICAL10.0
CVE-2025-29972 PoCAzure Storage Resource Provider Spoofing VulnerabilityCRITICAL9.9
CVE-2025-29827Azure Automation Elevation of Privilege VulnerabilityCRITICAL9.9
vulnfeed aggregates 7640 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.