← back
CVE-2024-38106

Windows Kernel Elevation of Privilege Vulnerability

CVSS 7 HIGHEPSS 6.3%● KEVCWE-591
In short

A flaw in the Windows Kernel allows an attacker with local access to run programs with higher privileges than they should have. This is dangerous because it can give an attacker full control over your computer.

Technical detail

An elevation of privilege vulnerability in the Windows Kernel (CWE-591: Sensitive Data Exposure through Query Strings) allows a local authenticated attacker to escalate privileges to SYSTEM level through kernel-mode operations. Exploitation requires local access and the ability to execute code, resulting in complete system compromise.

Summary generated and translated by AI from the official description.
Windows Kernel Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →