Executive brief
The Microsoft Windows Kernel contains an exposed IOCTL dispatcher in the appid.sys driver with insufficient access control. A local attacker can exploit this vulnerability to achieve elevation of privilege, potentially gaining kernel-level execution.
Affected products
- Microsoft Windows 10 1809 up to (excluding) 10.0.17763.5458
- Microsoft Windows 10 21H2 up to (excluding) 10.0.19044.4046
- Microsoft Windows 10 22H2 up to (excluding) 10.0.19045.4046
- Microsoft Windows Kernel
Timeline
- 2024-02-20: disclosed: Initial analysis by NIST
- 2024-03-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-03-04: exploited: Reported as exploited in the wild by Lazarus Group