CVE-2024-21345

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 13, 2024
Updated: May 29, 2024
CWE ID 122

Summary

CVE-2024-21345 is a newly identified Windows Kernel vulnerability that grants attackers elevated privileges. By exploiting this EoP (Elevation of Privilege) flaw, an attacker can potentially gain administrative access to affected systems, allowing them to install malware, modify or delete data, and carry out other malicious activities. The exact cause of the vulnerability remains undisclosed, but Microsoft urges users to apply patches as soon as they become available to mitigate potential threats. Local attackers can exploit this vulnerability through specially crafted applications or malicious files, placing systems at significant risk if left unpatched.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share