LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-38107: Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 13, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 3, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-38107 to its Known Exploited Vulnerabilities catalog on Aug 13, 2024, with a federal patch deadline of Sep 3, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges.

CVE-2024-38107 is a privilege escalation vulnerability in the Microsoft Windows Power Dependency Coordinator. It allows a local attacker who already has some access on a system to elevate privileges and obtain SYSTEM-level rights. This matters because SYSTEM access gives an attacker full control over the host, enabling further lateral movement, persistence, or data access once an initial foothold exists. Public detail on exact affected builds is limited, so teams must confirm against the vendor advisory.

The issue is tracked as CWE-416 (use-after-free). CISA notes that the Power Dependency Coordinator component contains an unspecified flaw that can be abused for local privilege escalation to SYSTEM. Known ransomware use is not documented.

How it works

Use-after-free flaws occur when software continues to reference memory after it has been freed. An attacker who can influence the timing or content of that memory can sometimes corrupt control structures or inject malicious data that the component later trusts. In this case the vulnerable component is the Windows Power Dependency Coordinator. A local attacker with the ability to run code or interact with the coordinator can trigger the condition and elevate to SYSTEM privileges. Exact exploit mechanics are not publicly detailed beyond the CWE class and the CISA summary; defenders should treat any local code execution path as a potential trigger and confirm technical specifics only against Microsoft’s advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the Power Dependency Coordinator component. This component is part of the core Windows power-management stack and is present on most modern Windows client and server installations. Inventory every Windows endpoint and server in your environment—workstations, laptops, domain controllers, member servers, and virtual machines—using your existing asset-management or endpoint-detection tools.

Specific version ranges and configuration flags are not provided here; always validate against the official Microsoft advisory before declaring a system safe.

How to remediate

The primary remediation is to apply the security update that Microsoft released for this vulnerability. Follow the vendor instructions exactly: download the appropriate cumulative update or standalone package for each Windows edition and architecture, test in a representative environment, then deploy via your standard patch-management process (WSUS, SCCM, Intune, or equivalent).

CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. In practice that means patching Windows or isolating unpatchable systems.

If you can't patch immediately

When immediate patching is blocked by change freezes or compatibility concerns, apply compensating controls that reduce the likelihood of successful local elevation.

These measures lower risk but do not eliminate it; schedule the official update as soon as operationally feasible.

If your data may have been exposed

Actively exploited local privilege-escalation vulnerabilities frequently become stepping stones to broader compromise and data exposure. If you discover evidence that CVE-2024-38107 was abused on any host, treat that system as potentially breached: isolate it, collect forensic artifacts, and begin incident-response procedures. Even without confirmed exploitation, organizations should assume that any unpatched Windows host that allowed local access may have been targeted. You can run a free exposure scan of your email addresses to check whether credentials or personal data already appear in known breach collections; this helps prioritize password resets and further investigation.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-416
Added to CISA KEVAug 13, 2024
Federal patch deadlineSep 3, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities