CVE-2024-35250
KEVmass1Local Privilege Escalation in Microsoft Windows Kernel-Mode Driver
CISA: Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability
CVE-2024-35250 is an untrusted pointer dereference flaw (CWE-822) in a Microsoft Windows kernel-mode driver, where a pointer supplied by untrusted code is mishandled. A local attacker who can already execute code on a vulnerable Windows system can trigger the flaw to run code in kernel context. Successful exploitation yields elevation of privilege, typically to SYSTEM-level rights, which can be chained with other weaknesses for fuller system compromise. Practically all Windows installations are potentially affected, though the bug is not remotely exploitable and requires an attacker to first gain local access. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-12-16, EPSS assigns a 25% probability of exploitation within 30 days (98th percentile), and no public PoC is known.
What to do: Apply Microsoft's security updates immediately — the flaw was fixed in Microsoft's June 2024 Patch Tuesday release, so confirm affected hosts are at or beyond that patch level using Microsoft's advisory and your patch telemetry. Because exploitation requires a local foothold, prioritize multi-user servers, shared workstations, and RDS/VDI hosts, and treat this bug as an escalation vector when hunting post-compromise activity. CISA KEV requires applying vendor mitigations (or discontinuing use) by the stated deadline; ransomware use is currently unknown.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-822
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H