LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-38106: Microsoft Windows Kernel Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 13, 2024
CVSS 7.0 · High⚠ Actively exploited (CISA KEV)
7.0
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 3, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-38106 to its Known Exploited Vulnerabilities catalog on Aug 13, 2024, with a federal patch deadline of Sep 3, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-38106 is a privilege escalation vulnerability in the Microsoft Windows Kernel. A local attacker who can win a race condition may elevate to SYSTEM privileges. This matters because SYSTEM-level access lets an attacker disable security controls, persist, move laterally, or access sensitive data on the host. Confirm exact impact and affected builds against the Microsoft advisory.

CISA notes the issue allows privilege escalation after winning a race condition. Known ransomware use is not documented for this CVE. Treat any successful local elevation as high risk and prioritize remediation.

How it works

The weakness is classified as CWE-591. In the Windows Kernel, an unspecified condition creates a race that a local attacker can attempt to win. If successful, the attacker obtains SYSTEM privileges. Public detail is limited to the race-condition requirement and the resulting elevation; do not assume specific memory objects, timing windows, or call sequences beyond what the vendor advisory states.

Exploitation requires local code execution or an existing low-privilege foothold. Remote unauthenticated attack is not indicated by the available facts. Once SYSTEM is obtained, the attacker can perform any action the kernel allows under that identity.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. Inventory every Windows endpoint and server in your environment—workstations, domain controllers, member servers, virtual machines, and cloud-hosted Windows instances. Use asset management tools, SCCM/ConfigMgr, Intune, or PowerShell queries against the OS build and patch level to identify systems that have not yet received the vendor update for this CVE.

If your inventory shows unpatched Windows hosts, treat them as potentially vulnerable until the update is applied and verified.

How to remediate

Apply the Microsoft security update that addresses CVE-2024-38106 as the primary remediation. Follow the vendor instructions exactly for deployment, reboot requirements, and verification. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Once patched, re-baseline privilege-escalation detections and continue monitoring for residual footholds that may have been established before remediation.

If you can't patch immediately

Reduce the attack surface and limit the value of a successful race until the update can be applied.

These steps do not eliminate the vulnerability; they only lower the likelihood and impact of exploitation until the official update is installed.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities can lead to full host compromise and subsequent data exposure. If you have evidence of successful exploitation or unexplained SYSTEM activity, treat the host as compromised: isolate it, preserve forensic artifacts, and begin incident response. Review whether credentials, files, or other sensitive material were accessible under SYSTEM. Readers can run a free exposure scan of their email addresses against known breach data sets to check for prior credential exposure that might have enabled the initial foothold.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-591
CVSS base score7.0 (High)
CVSS vectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
PublishedAug 13, 2024
Added to CISA KEVAug 13, 2024
Federal patch deadlineSep 3, 2024
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities