CVE-2024-21338

Published Feb 13, 2024

Last updated 9 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-21338 is an elevation of privilege vulnerability found within the Windows kernel, specifically residing in the `appid.sys` AppLocker driver. This flaw allows an attacker with low-privileged local code execution to escalate their privileges to SYSTEM-level by exploiting an exposed Input/Output Control (IOCTL) handler. The vulnerability stems from insufficient validation of user-supplied input within the `AppHashComputeImageHashInternal()` function, which can be invoked by sending a specially crafted IOCTL request to the `\Device\Appid` device object. By manipulating this IOCTL request, an attacker can cause the driver to execute an attacker-chosen routine in kernel context, effectively crossing the admin-to-kernel security boundary. This vulnerability affects supported versions of Windows 10, Windows 11, and Windows Server.

Description
Windows Kernel Elevation of Privilege Vulnerability
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_21h2, windows_11_22h2, windows_11_23h2, windows_server_2019, windows_server_2022, windows_server_2022_23h2

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability
Exploit added on
Mar 4, 2024
Exploit action due
Mar 25, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

secure@microsoft.com
CWE-822
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. 【独自】米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログで、以下の3件の脆弱性のランサムウェアによる悪用が確認済みとなった。 - WindowsカーネルIOCTLの権限昇格CVE-2024-21338 - Adobe… https://t.co/oJlYDo1JFS https://t.co/8wc0frfQI0

    @__kokumoto

    2294 Impressions

    1 Retweet

    16 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  2. すべてのWindowsに標準搭載されたドライバーを悪用し、管理者からカーネルへ権限昇格できるCVE-2024-21338の解説とPoCが公開されています。脆弱なドライバーを外部から持ち込む従来のBYOVD(Bring-Your-Own-Vulnerable-Dri

    @MalwareBibleJP

    13 Jul 2026

    3097 Impressions

    10 Retweets

    38 Likes

    22 Bookmarks

    0 Replies

    0 Quotes

  3. Lazarus used this as a zero-day. No BYOVD needed. The vulnerable driver is already on every Windows machine. CVE-2024-21338 exploits appid.sys (AppLocker's driver) to call a user-controlled function pointer in kernel mode. The exploit uses ExpProfileDelete as a valid kCFG target

    @cr3ghost

    12 Jul 2026

    39346 Impressions

    88 Retweets

    453 Likes

    298 Bookmarks

    6 Replies

    2 Quotes

  4. 00:00 UTC: CVE-2024-21338 disclosed. CISA: CVE-2024-21338 added to Known Exploited Vulnerabilities — Microsoft Windows Status: ✅ Confirmed exploited in the wild Date added: 2024-03-04 Required action: Apply mitigations per vendor instructions or discontinue use of the…

    @lyrie_ai

    3 May 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Dropped 2 Writeups Windows & Driver Internals → Exploitation Kernel Exploit ( CVEs + Root Cause → Exploit) • CVE-2025-62215 • CVE-2024-30088 • CVE-2024-21338 • Stack Overflow & Arbitrary Overwrite (Kernel) https://t.co/TAj4v5rG1v #ExploitDevelopment

    @0XDbgMan

    15 Feb 2026

    68 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Windows AppLocker Driver LPE Vulnerability – CVE-2024-21338 https://t.co/JjzanvUcQs

    @Hussein_Kahsay

    25 Mar 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. [Research] Bypassing Windows Kernel Mitigations: Part 2 - CVE-2024-21338 Dive into bypassing kCFG with a Local Privilege Escalation exploit in appid.sys (CVE-2024-21338). https://t.co/iuKVrBHZqk Coming soon: Part 3! https://t.co/1l7oWWq6qp

    @hackyboiz

    12 Jan 2025

    2070 Impressions

    21 Retweets

    60 Likes

    35 Bookmarks

    0 Replies

    0 Quotes

  8. Bypassing Windows Kernel Mitigations Part 2 - CVE-2024-21338 Dive into bypassing kCFG with a Local Privilege Escalation exploit in appid.sys (CVE-2024-21338). https://t.co/iuKVrBIxfS Coming soon: Part 3! https://t.co/0Rq0ATS5ZT

    @hackyboiz

    12 Jan 2025

    43 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

Configurations