ZeroHour

CVE-2024-30088

KEV ransomwaremass1

Microsoft Windows Kernel TOCTOU Race Condition Privilege Escalation (CVE-2024-30088)

CISA: Microsoft Windows Kernel TOCTOU Race Condition Vulnerability

CVSS 3.1
7.0 high
EPSS
68%p99
Published
()
KEV added
AI analysis

CVE-2024-30088 is a time-of-check to time-of-use (TOCTOU) race condition in the Microsoft Windows kernel (CWE-367) that allows a local, low-privileged attacker to elevate to SYSTEM-level privileges. Because it is a timing race with high attack complexity, exploitation requires locally executing crafted code that repeatedly races the kernel's validation of a resource, but no user interaction is needed and the attacker only needs the ability to already run code on the target. Successful exploitation grants full control of the local machine (high confidentiality, integrity, and availability impact), which attackers typically chain after initial access or another flaw to gain complete host compromise. Virtually all supported Windows 10 and Windows 11 client releases and Windows Server 2016 through 2022 23H2 are affected if unpatched. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-15 with known ransomware use, Iran-linked OilRig used it in an espionage campaign targeting UAE and Gulf governments, and EPSS assigns a ~68% probability of exploitation within 30 days (99th percentile).

What to do: Apply the Windows cumulative security update for CVE-2024-30088 from Microsoft's advisory on every affected Windows 10, Windows 11, and Windows Server release (the fix shipped in Microsoft's June 2024 monthly security updates; confirm your build number against the advisory). Prioritize multi-user hosts, RDP/jump servers, and endpoints where untrusted users or code run, since this is a local privilege escalation used post-compromise — check endpoint logs for suspicious local process activity coinciding with privilege changes. Consistent with the CISA KEV required action (added 2024-10-15), patch promptly per vendor instructions or discontinue use of affected builds if patching is not possible.

Affected
microsoft Windows 101507, 1607, 1809, 21H2, 22H2
microsoft Windows 1121H2, 22H2, 23H2
microsoft Windows Server2016, 2019, 2022, 2022 23H2
Estimated exposure
mass≈1 billion+ Windows 10/11 client devices and hundreds of thousands to millions of Windows Server hosts (unpatched installed base) — Windows 10/11 account for the vast majority of Microsoft's reported ~1.4 billion active Windows devices and Windows Server 2016–2022 is deployed on hundreds of thousands to millions of hosts worldwide, so the plausibly affected unpatched…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Kernel Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
Weakness
CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news