Forum Discussion
CVE-2024-43484
Has anyone been able to remediate CVE-2024-43484? I do actually see the vulnerable file version on machines in this location: C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\System.io.compression.dll has version 4.8.9221.0. Okay, so I download KB5066131 which says in it's file information csv that it updates this .dll to file version 4.8.9277.0. I try to install it and get a message that the KB is not applicable to my system. I run the commands to extrand the .cab file then install it with DISM and reboot the machine...but the file version doesn't update. So I look at the latest KB that superceeded KB5066131which is as of today september's KB5126052 but when you look at the listed file information csv it says it reverts this file back to version 4.8.9221.0. I'm so confussed now. Was this a Microsoft mistake or is there an actual fix to this?