Microsoft patched a high-severity Windows Kernel privilege escalation vulnerability in February, six months after being informed that the flaw was being exploited as a zero-day. Tracked as CVE-2024-21338, the security flaw was found by Avast Senior Malware Researcher Jan Vojtěšek in the appid.sys Windows AppLocker driver and reported to Microsoft last August as an actively exploited zero-day. The vulnerability impacts systems running multiple versions of Windows 10 and Windows 11 (including the latest releases), as well as Windows Server 2019 and 2022. Microsoft explains that successful exploitation enables local attackers to gain SYSTEM privileges in low-complexity attacks that don't require user interaction. "To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system," Redmond says. The company patched the vulnerability on February 13 and updated the advisory on Wednesday, February 28, to confirm that CVE-2024-21338 had been exploited in the wild, but it didn't disclose any details regarding the attacks. However, Avast told BleepingComputer that the North Korean Lazarus state hackers have been exploiting the flaw in attacks as a zero-day since at least August 2023 to gain kernel-level access and turn off security tools, allowing them to avoid using easier-to-detect BYOVD (Bring Your Own Vulnerable Driver) technique...
Windows Kernel bug fixed last month exploited as zero-day since August
BleepingComputer
·Sergiu Gatlan
·Published Mar 2, 2024
·Updated
Affected Software
5 affected components
Microsoft Windows Kernel
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a high-severity Windows Kernel bug that was exploited as a zero-day for several months before being patched by Microsoft.
2
What security implications are discussed?
The article highlights the risks associated with zero-day vulnerabilities that allow privilege escalation, potentially enabling attackers to gain unauthorized access to systems.
3
What products or software are affected?
The affected software includes Microsoft Windows Kernel, Windows 10, Windows 11, Windows Server 2019, and Windows Server 2022.
4
When was the Windows Kernel bug first exploited as a zero-day?
The Windows Kernel bug was exploited as a zero-day since August before being patched in February.
5
What is the identifier for the Windows Kernel vulnerability?
The vulnerability is tracked as CVE-2024-21338.