When will Windows update the built-in curl.exe to address CVE-2024-9681?

Sai Ganesh Thorthi 0 Reputation points
2025-06-29T00:43:36.61+00:00

Hello Microsoft team,

I'm reaching out to ask when Windows plans to update the built-in curl.exe binary (located in C:\Windows\System32) to address CVE-2024-9681. This vulnerability was patched upstream in curl 8.11.0, released on November 6, 2024.

Currently, Windows still ships older versions of curl (e.g., 7.83.1 in some systems), which are vulnerable. As replacing this binary manually is not recommended and may interfere with Windows system operations or updates, we are waiting for an official patch via Windows Update or cumulative updates.

Could Microsoft provide any information or a release timeline for when the built-in curl binary will be updated?

References:

Thanks in advance for your help and clarification.

Windows for business | Windows Server | Devices and deployment | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Brian Huynh (WICLOUD CORPORATION) 390 Reputation points Microsoft External Staff Moderator
    2025-07-09T07:12:30.15+00:00

    Hello, Thank you for raising the question.  

    Regarding a specific release timeline, Microsoft does not typically pre-announce release dates for security updates for individual components. This is a standard security practice to protect customers. 

    When an update for a third-party component like curl is validated and ready for deployment, it is serviced and delivered via Windows Update. These patches are most often included in the monthly Cumulative Updates

    The best way to determine if a specific CVE has been addressed by Microsoft is to monitor the MSRC Security Update Guide. This is the definitive source for information on security vulnerabilities in Microsoft products. 

    You can search the MSRC portal directly for CVE-2024-9681. If a Windows update has been released to address this vulnerability, all relevant details, including the affected products and the KB articles that contain the fix, will be listed there. 

    Hope this provides clarity on the process. 

    Best regards. 


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.