CVE-2024-38144

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Aug 13, 2024
Updated: Aug 16, 2024
CWE ID 190

Summary

CVE-2024-38144 is an elevation of privilege vulnerability affecting the Kernel Streaming WOW Thunk Service Driver. This issue allows an attacker to manipulate the service to gain elevated system privileges on a Windows system. Successful exploitation could potentially lead to the compromise of the entire system. The vulnerability is significant due to its potential impact on system security and the need for affected systems to be patched as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows
  • Microsoft Windows 11
  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft