CVE-2024-21338CISA KEV
Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.
- Product
- Windows
- Added to KEV
- 4 Mar 2024
- Federal remediation due
- 25 Mar 2024
- Known ransomware use
- Yes