Junglewise Threat Intelligence

CVE-2024-21338: Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability

CVE-2024-21338 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2024-03-04

Technologies: Microsoft Windows Kernel, Microsoft Windows, Microsoft Windows 10 22h2, Microsoft Windows 10 21h2, Microsoft Windows 10 1809. Vendors: Microsoft.

Executive brief

The Microsoft Windows Kernel contains an exposed IOCTL dispatcher in the appid.sys driver with insufficient access control. A local attacker can exploit this vulnerability to achieve elevation of privilege, potentially gaining kernel-level execution.

Affected products

  • Microsoft Windows 10 1809 up to (excluding) 10.0.17763.5458
  • Microsoft Windows 10 21H2 up to (excluding) 10.0.19044.4046
  • Microsoft Windows 10 22H2 up to (excluding) 10.0.19045.4046
  • Microsoft Windows Kernel

Timeline

  • 2024-02-20: disclosed: Initial analysis by NIST
  • 2024-03-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-03-04: exploited: Reported as exploited in the wild by Lazarus Group

Related threats