CVE-2024-38080
KEVmass1Actively Exploited Local Privilege Escalation in Microsoft Windows Hyper-V
CISA: Microsoft Windows Hyper-V Privilege Escalation Vulnerability
CVE-2024-38080 is an integer-overflow (CWE-190) elevation-of-privilege vulnerability in the Windows Hyper-V component, rated 7.8 (High). It is triggered locally: an attacker who can already run low-privileged code on an affected Windows 11 or Windows Server 2022 host can exploit it without user interaction. Successful exploitation allows the attacker to elevate privileges, with high impact on confidentiality, integrity, and availability of the affected system. Affected systems include Windows 11 21H2, 22H2, and 23H2 and Windows Server 2022 (including the 2022 23H2 update) running the vulnerable Hyper-V code. Microsoft patched the flaw in its July 2024 Patch Tuesday release, and it is being actively exploited in the wild; it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-09 alongside the other actively exploited July zero-day, CVE-2024-38112.
What to do: Apply Microsoft's July 2024 (July 9, 2024 Patch Tuesday) cumulative security updates for Windows 11 21H2/22H2/23H2 and Windows Server 2022 immediately, prioritizing hosts and endpoints where the Hyper-V platform or role is enabled; per CISA KEV requirements, federal agencies must apply the vendor fixes within the mandated deadline. Inventory systems running the affected versions, confirm the update is installed after reboot, and restrict untrusted local code execution on Hyper-V hosts until patching is complete.
| Microsoft Windows 11 21H2 | all builds prior to the July 2024 cumulative security update |
| Microsoft Windows 11 22H2 | all builds prior to the July 2024 cumulative security update |
| Microsoft Windows 11 23H2 | all builds prior to the July 2024 cumulative security update |
| Microsoft Windows Server 2022 | all builds prior to the July 2024 cumulative security update |
| Microsoft Windows Server 2022 23H2 | all builds prior to the July 2024 cumulative security update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Hyper-V Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2022, windows server 2022 23h2
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H