CVE-2024-38125

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Aug 13, 2024
Updated: Aug 16, 2024
CWE ID 197

Summary

CVE-2024-38125 is a newly disclosed kernel vulnerability affecting the Streaming WOW64 (Winsub) Thunk Service Driver. This issue allows an attacker to elevate their privileges, potentially gaining administrative access to a compromised system. The vulnerability exists due to improper handling of user input in the driver, enabling attackers to execute arbitrary code in the context of the system. Successful exploitation could result in serious consequences, including data theft, system damage, or unauthorized access. System administrators are urged to apply patches as soon as they become available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows
  • Microsoft Windows 11
  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft