CVE-2024-35250: Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability
Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges.
Other sources
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27170Patch KB5039274 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22023Patch KB5039294 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24919Patch KB5039260 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22720Patch KB5039266 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7070Patch KB5039214 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.950Patch KB5039236 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20680Patch KB5039225 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.3737Patch KB5039212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.4529Patch KB5039211 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.3737Patch KB5039212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.4529Patch KB5039211 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2527Fixed in 10.0.20348.2522Patch KB5039330 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.3019Patch KB5039213 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.5936Patch KB5039217
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35250?
CVE-2024-35250 is classified as a critical elevation of privilege vulnerability in Microsoft Windows.
How do I fix CVE-2024-35250?
To fix CVE-2024-35250, apply the latest security patches provided by Microsoft for affected Windows versions.
Which versions of Windows are affected by CVE-2024-35250?
CVE-2024-35250 affects multiple versions of Microsoft Windows, including Windows 10, Windows 11, and Windows Server editions.
Can CVE-2024-35250 be exploited remotely?
No, CVE-2024-35250 requires local access to the system for exploitation.
What are the consequences of exploiting CVE-2024-35250?
Exploiting CVE-2024-35250 can allow an attacker to escalate their privileges and potentially gain control over the system.