CVE-2024-30088: Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.
Other sources
Windows Kernel Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7070Patch KB5039214 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20680Patch KB5039225 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.3737Patch KB5039212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.4529Patch KB5039211 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.950Patch KB5039236 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.3019Patch KB5039213 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.3737Patch KB5039212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.4529Patch KB5039211 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2527Fixed in 10.0.20348.2522Patch KB5039330 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.5936Patch KB5039217
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30088?
CVE-2024-30088 is classified as a critical elevation of privilege vulnerability in Microsoft Windows Kernel.
How do I fix CVE-2024-30088?
To fix CVE-2024-30088, apply the appropriate security updates from Microsoft, specifically KB5039211 for Windows 10 and KB5039212 for Windows 11.
Which Windows versions are affected by CVE-2024-30088?
CVE-2024-30088 affects Windows 10 (21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), and Windows Server 2016, 2019, and 2022.
Can CVE-2024-30088 be exploited remotely?
CVE-2024-30088 is an elevation of privilege vulnerability and requires local access to exploit.
What mechanisms allow the exploitation of CVE-2024-30088?
The vulnerability stems from a time-of-check to time-of-use (TOCTOU) race condition in the Windows Kernel.