Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability
High CVSS 7.8 Listed in CISA KEV
Summary
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Microsoft:Windows
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2024-21338 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21338; reference
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21338 Patch
- https://decoded.avast.io/janvojtesek/lazarus-and-the-fudmodule-rootkit-beyond-byovd-with-an-admin-to-kernel-zero-day/ Exploit
- https://packetstorm.news/files/id/190586/ Exploit
- https://www.exploit-db.com/exploits/52275 Exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21338 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD