• News/
  • https://www.bleepingcomputer.com/news/security/windows-kernel-bug-fixed-last-month-exploited-as-zero-day-since-august/

Windows Kernel bug fixed last month exploited as zero-day since August

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 2, 2024
·
Updated

Microsoft patched a high-severity Windows Kernel privilege escalation vulnerability in February, six months after being informed that the flaw was being exploited as a zero-day. Tracked as CVE-2024-21338, the security flaw was found by Avast Senior Malware Researcher Jan Vojtěšek in the appid.sys Windows AppLocker driver and reported to Microsoft last August as an actively exploited zero-day. The vulnerability impacts systems running multiple versions of Windows 10 and Windows 11 (including the latest releases), as well as Windows Server 2019 and 2022. Microsoft explains that successful exploitation enables local attackers to gain SYSTEM privileges in low-complexity attacks that don't require user interaction. "To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system," Redmond says. The company patched the vulnerability on February 13 and updated the advisory on Wednesday, February 28, to confirm that CVE-2024-21338 had been exploited in the wild, but it didn't disclose any details regarding the attacks. However, Avast told BleepingComputer that the North Korean Lazarus state hackers have been exploiting the flaw in attacks as a zero-day since at least August 2023 to gain kernel-level access and turn off security tools, allowing them to avoid using easier-to-detect BYOVD (Bring Your Own Vulnerable Driver) technique...

Read full article

Affected Software

5 affected components
Microsoft Windows Kernel
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows Server 2019
Microsoft Windows Server 2022

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a high-severity Windows Kernel bug that was exploited as a zero-day for several months before being patched by Microsoft.

2

What security implications are discussed?

The article highlights the risks associated with zero-day vulnerabilities that allow privilege escalation, potentially enabling attackers to gain unauthorized access to systems.

3

What products or software are affected?

The affected software includes Microsoft Windows Kernel, Windows 10, Windows 11, Windows Server 2019, and Windows Server 2022.

4

When was the Windows Kernel bug first exploited as a zero-day?

The Windows Kernel bug was exploited as a zero-day since August before being patched in February.

5

What is the identifier for the Windows Kernel vulnerability?

The vulnerability is tracked as CVE-2024-21338.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203