CVE-2024-21345

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 13, 2024
Updated: May 29, 2024
CWE ID 122

Summary

CVE-2024-21345 is a newly identified Windows Kernel vulnerability that grants attackers elevated privileges. By exploiting this EoP (Elevation of Privilege) flaw, an attacker can potentially gain administrative access to affected systems, allowing them to install malware, modify or delete data, and carry out other malicious activities. The exact cause of the vulnerability remains undisclosed, but Microsoft urges users to apply patches as soon as they become available to mitigate potential threats. Local attackers can exploit this vulnerability through specially crafted applications or malicious files, placing systems at significant risk if left unpatched.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-21345 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions