ZeroHour

CVE-2024-38080

KEVmass1

Actively Exploited Local Privilege Escalation in Microsoft Windows Hyper-V

CISA: Microsoft Windows Hyper-V Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
7%p94
Published
()
KEV added
AI analysis

CVE-2024-38080 is an integer-overflow (CWE-190) elevation-of-privilege vulnerability in the Windows Hyper-V component, rated 7.8 (High). It is triggered locally: an attacker who can already run low-privileged code on an affected Windows 11 or Windows Server 2022 host can exploit it without user interaction. Successful exploitation allows the attacker to elevate privileges, with high impact on confidentiality, integrity, and availability of the affected system. Affected systems include Windows 11 21H2, 22H2, and 23H2 and Windows Server 2022 (including the 2022 23H2 update) running the vulnerable Hyper-V code. Microsoft patched the flaw in its July 2024 Patch Tuesday release, and it is being actively exploited in the wild; it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-09 alongside the other actively exploited July zero-day, CVE-2024-38112.

What to do: Apply Microsoft's July 2024 (July 9, 2024 Patch Tuesday) cumulative security updates for Windows 11 21H2/22H2/23H2 and Windows Server 2022 immediately, prioritizing hosts and endpoints where the Hyper-V platform or role is enabled; per CISA KEV requirements, federal agencies must apply the vendor fixes within the mandated deadline. Inventory systems running the affected versions, confirm the update is installed after reboot, and restrict untrusted local code execution on Hyper-V hosts until patching is complete.

Affected
Microsoft Windows 11 21H2all builds prior to the July 2024 cumulative security update
Microsoft Windows 11 22H2all builds prior to the July 2024 cumulative security update
Microsoft Windows 11 23H2all builds prior to the July 2024 cumulative security update
Microsoft Windows Server 2022all builds prior to the July 2024 cumulative security update
Microsoft Windows Server 2022 23H2all builds prior to the July 2024 cumulative security update
Estimated exposure
massplausibly >1,000,000 systems — on the order of tens of millions of Windows 11 and Windows Server 2022 hosts, given the subset where the Hyper-V platform is… — Hyper-V is the hypervisor platform built into Windows 11 (Pro/Enterprise) and Windows Server 2022, whose combined installed bases run into the hundreds of millions of devices, so even the fraction of hosts with Hyper-V active plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Hyper-V Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2022, windows server 2022 23h2
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news