CVE-2024-38106
KEVmass2Local Privilege Escalation in Microsoft Windows Kernel (CVE-2024-38106)
CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability
CVE-2024-38106 is an elevation-of-privilege flaw in the Microsoft Windows kernel caused by a deleted-reference memory-safety weakness (CWE-591), a use-after-free-class bug that corrupts kernel memory. A local attacker with valid low-privileged credentials must run a specially crafted application to trigger the flaw; the attack is local with no user interaction required but is rated high in attack complexity (CVSS:3.1/AV:L/AC:H/PR:L/UI:N, 7.0 High). Successful exploitation elevates the attacker to kernel/SYSTEM-level privileges, giving full control of the compromised host. All supported Windows 10 branches (1507 through 22H2), Windows 11 (21H2 through 24H2), and Windows Server 2016, 2019, and 2022 are affected, meaning essentially the entire current Windows install base. The flaw is confirmed exploited in the wild: CISA added it to the KEV catalog on 2024-08-13, and headlines show it is among the six actively exploited zero-days Microsoft fixed in its August 2024 Patch Tuesday release; no public proof-of-concept is known, and EPSS estimates a 6.3% probability of exploitation in the next 30 days (93rd percentile).
What to do: Apply the August 2024 Patch Tuesday cumulative updates (released August 13, 2024) via Windows Update, WSUS, or Intune to every affected Windows 10, Windows 11, or Windows Server instance; this is a KEV-listed, actively exploited bug, so prioritize it in patch cycles. Until patched, restrict local code execution by untrusted or low-privileged users on high-value hosts and hunt for signs of unexpected local privilege escalation. Per CISA's required action, apply vendor mitigations per Microsoft's instructions or discontinue use of affected systems if mitigations are unavailable.
| microsoft Windows 10 1507 | all supported builds of the 1507 branch prior to the August 2024 security updates |
| microsoft Windows 10 1607 | all supported builds of the 1607 branch prior to the August 2024 security updates |
| microsoft Windows 10 1809 | all supported builds of the 1809 branch prior to the August 2024 security updates |
| microsoft Windows 10 21H2 | all supported builds of the 21H2 branch prior to the August 2024 security updates |
| microsoft Windows 10 22H2 | all supported builds of the 22H2 branch prior to the August 2024 security updates |
| microsoft Windows 11 21H2 | all supported builds of the 21H2 branch prior to the August 2024 security updates |
| microsoft Windows 11 22H2 | all supported builds of the 22H2 branch prior to the August 2024 security updates |
| microsoft Windows 11 23H2 | all supported builds of the 23H2 branch prior to the August 2024 security updates |
| microsoft Windows 11 24H2 | all supported builds of the 24H2 branch prior to the August 2024 security updates |
| microsoft Windows Server 2016 | all supported builds prior to the August 2024 security updates |
| microsoft Windows Server 2019 | all supported builds prior to the August 2024 security updates |
| microsoft Windows Server 2022 | all supported builds prior to the August 2024 security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Kernel Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-591
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H