critical
CISA KEV
Ransomware
CVE-2024-21338
Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability
// Description
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.
// Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Federal remediation due Mar 25, 2024 — past due
Advertisement