ZeroHour

CVE-2024-38107

KEVmass1

Use-After-Free Privilege Escalation in Microsoft Windows Power Dependency Coordinator

CISA: Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p75
Published
()
KEV added
AI analysis

CVE-2024-38107 is a use-after-free (CWE-416) elevation-of-privilege vulnerability in the Windows Power Dependency Coordinator, rated 7.8 High (local attack, low required privileges, high impact on confidentiality, integrity and availability). It is triggered locally: an attacker who already holds valid low-privileged credentials and can execute code on a target Windows machine abuses the memory-handling bug to run code at elevated privilege. Successful exploitation yields high-privilege (kernel/SYSTEM-level) access on the host, enabling credential theft and follow-on activity such as malware or ransomware deployment. Affected products span Windows 10 (1507 through 22H2), Windows 11 (21H2 through 24H2) and Windows Server 2012/2016/2019, i.e., nearly the entire currently supported Windows installed base. The flaw is under active exploitation: CISA added it to the KEV on 2024-08-13 and it is one of six actively exploited zero-days patched in Microsoft's August 2024 Patch Tuesday; no public PoC is known and whether ransomware groups use it is unknown.

What to do: Apply Microsoft's August 2024 Patch Tuesday cumulative security updates (released August 13, 2024) to all affected Windows 10, Windows 11 and Windows Server systems, prioritizing hosts where untrusted or low-privileged users can run code. Because exploitation requires local access, review local user privileges and hunt for local privilege escalation activity on endpoints. Per CISA's KEV required action, apply vendor mitigations or discontinue use of affected Windows versions if updates are unavailable.

Affected
Microsoft Windows 101507, 1607, 1809, 21H2, 22H2
Microsoft Windows 1121H2, 22H2, 23H2, 24H2
Microsoft Windows Server2012, 2016, 2019
Estimated exposure
masshundreds of millions of Windows endpoints and servers (the affected version range covers nearly the entire supported Windows 10/11 and Windows Server installed… — Windows runs on over a billion active devices and the affected versions span all currently supported Windows client and server releases, so the plausible affected population is the bulk of the supported installed base; the KEV listing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news