0-day in Windows driver exploited by North Korean hackers to deliver rootkit (CVE-2024-38193)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-38193 | Use-After-Free Privilege Escalation in Microsoft Windows WinSock Driver (afd.sys) The Windows Ancillary Function Driver for WinSock (afd.sys) contains a use-after-free flaw (CWE-416) that allows a local attacker to escalate privileges. An attacker who can already execute code on a Windows host — typically after gaining initial access via phishing, malware, or chaining with another vulnerability — triggers the bug to gain SYSTEM-level privileges, giving them near-full control of the machine. Any Windows host running an affected build is exposed to the flaw, though it requires local code execution and is not remotely exploitable on its own. Exploitation is confirmed in the wild: CISA added the CVE to the KEV catalog on 2024-08-13 and Microsoft shipped fixes in its August 2024 security updates, while the ransomware association is currently listed as unknown. EPSS is elevated at 28.5% (98th percentile), indicating a high likelihood of continued exploitation over the next 30 days. Do: Apply Microsoft's August 2024 Windows cumulative security updates (released 2024-08-13) across all Windows clients and servers, prioritizing multi-user hosts such as RDS/VDI servers and jump boxes where local code execution by low-privileged users is more likely. After patching, verify installed build numbers and hunt for signs of local privilege escalation, per CISA's KEV required action to apply vendor mitigations or discontinue use. Keep the host within your KEV remediation SLA, as listing in the catalog signals active exploitation. | 7.8 | 29% | KEV PoC |
| mass>1 billion Windows endpoints worldwide, i.e., effectively every unpatched Windows client or server |
Full article477 words · extracted from helpnetsecurity.com · click to collapse
CVE-2024-38193, an actively exploited zero-day that Microsoft patched earlier this month, has been leveraged by North Korean hackers to install a rootkit on targets’ computers, Gen Digital researchers have revealed.
About CVE-2024-38193
CVE-2024-38193 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys).
Gen Digital researchers Luigino Camastra and Milanek discovered in early June 2024 that the Lazarus APT group was exploiting the flaw to achieve SYSTEM privilege, so they can “bypass normal security restrictions and access sensitive system areas that most users and administrators can’t reach.”
“We also discovered that they used a special type of malware called FudModule to hide their activities from security software,” the company now confirmed.
“This type of attack is both sophisticated and resourceful, potentially costing several hundred thousand dollars on the black market. This is concerning because it targets individuals in sensitive fields, such as those working in cryptocurrency engineering or aerospace to get access to their employer’s networks and steal crypto currencies to fund attackers’ operations.”
Exploiting vulnerable drivers
FudModule is a rootkit – a type of malware that, once installed, has access to the deepest levels of the operating system (e.g., kernel), can make changes to the system and can disable native and third-party security solutions.
The Lazarus group is well known for delivering rootkits to targets, either by:
- Taking advantage of zero-day vulnerabilities they found in Windows drivers that are installed by default, or by
- Installing vulnerable third-party drivers and taking advantage of their 0-day or n-day flaws (this is the so-called “Bring Your Own Vulnerable Driver” technique).
“If an attacker (…) manages to exploit a zero-day vulnerability in a built-in driver, they will be rewarded with a level of stealth that cannot be matched by standard BYOVD exploitation,” Avast researchers explained earlier this year.
“By exploiting such a vulnerability, the attacker is in a sense living off the land with no need to bring, drop, or load any custom drivers, making it possible for a kernel attack to be truly fileless. This not only evades most detection mechanisms but also enables the attack on systems where driver allowlisting is in place.”
How can potential victims check whether they have been saddled with the rootkit and further compromised by the Lazarus hackers? Gen Digital does not say.
We’ve reached out to the company to ask for more information, and we’ll update this piece if we hear back from them.
UPDATE (August 20, 2024, 11:20 a.m. ET):
The victim organizations are largely from the crypto currency sphere as well as aerospace, a Gen Digital representative has told us.
“The lead researchers following Lazarus also shared that they believe this campaign is the same as the last one,” they added.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/08/20/0-day-in-windows-driver-exploited-by-north-korean-hackers-to-deliver-rootkit-cve-2024-38193/