CVE-2024-21338Exploit(microsoft / windows_10_1809)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft windows_10_1809 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Windows Kernel Elevation of Privilege Vulnerability

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-03-25. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-822

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2
  • windows_11_21h2

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-03); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
windows_10_1809windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2windows_11_23h2windows_server_2019windows_server_2022windows_server_2022_23h2

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-02-15: 1Mentions · 2026-05-03: 2Mentions · 2026-07-08: 2Mentions · 2026-07-12: 1PoC Mentioned / Linked · 2026-02-15: 1PoC Mentioned / Linked · 2026-07-12: 1Exploit Tool / Code · 2026-07-12: 1Active Exploitation · 2026-05-03: 2Active Exploitation · 2026-07-12: 1Patch / Workaround · 2026-05-03: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-12: 102-1505-0307-0807-12
Signal classification3 categories
Exploit
233.3%
Active Exploitation
233.3%
General
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-151
Exploit1
2026-05-032
Active Exploitation2
2026-07-082
General2
2026-07-121
Exploit1
Full discourse6 posts
  • cr3ghost@cr3ghost
    Exploit

    Lazarus used this as a zero-day. No BYOVD needed. The vulnerable driver is already on every Windows machine. CVE-2024-21338 exploits appid.sys (AppLocker's driver) to call a user-controlled function pointer in kernel mode. The exploit uses ExpProfileDelete as a valid kCFG target to decrement PreviousMode from 1 to 0. Once PreviousMode is flipped, NtWriteVirtualMemory and NtReadVirtualMemory skip all security checks. Full admin-to-kernel LPE with token manipulation. Works on Windows 10 and 11 with HVCI enabled. Full PoC included. If you just read the PreviousMode mitigation post by @yarden_shafir, this is the CVE that forced Microsoft to add it. https://hakaisecurity.io/cve-2024-21338-from-admin-to-kernel-through-token-manipulation-and-windows-kernel-exploitation/research-blog/ https://github.com/hakaioffsec/CVE-2024-21338 Author: @HakaiOffsec #WindowsInternals #ExploitDevelopment #InfoSec

    Post summary

    The post announces that the CVE-2024-21338 zero‑day, used by Lazarus, allows full admin‑to‑kernel LPE via the AppLocker's driver; a PoC and exploit code are provided with detailed technical context.

    12120258636755.9K
    7.8K followersView on X
  • OS Dev@OSdev_
    General

    Windows security doesn't stop at SYSTEM. CVE-2024-21338 shows that even an administrator isn't necessarily at the highest privilege level. The vulnerability exists in "appid.sys" (AppLocker) and allows an attacker to cross the boundary from Administrator to kernel by abusing an untrusted pointer exposed through a kernel IOCTL. Once kernel code execution is achieved, the exploit manipulates process tokens to obtain full kernel privileges while bypassing protections such as HVCI. What makes the Hakai Security research worth reading isn't just the exploit, it's the journey from a vulnerable IOCTL to a reliable kernel exploit. The write-up covers IOCTL dispatching, kernel callbacks, PreviousMode abuse, token manipulation, HVCI-aware exploitation, and modern Windows kernel exploitation techniques. If you're interested in Windows internals, it's an excellent deep dive into how real-world kernel exploits are built.

    Post summary

    The message explains CVE‑2024‑21338, detailing how an administrator can elevate to kernel privileges through a driver flaw, but does not provide a PoC, exploit, active exploitation evidence, or patch information.

    224020610613.3K
    5.0K followersView on X
  • DbgMan ^_^@0XDbgMan
    Exploit

    Dropped 2 Writeups Windows & Driver Internals → Exploitation Kernel Exploit ( CVEs + Root Cause → Exploit) • CVE-2025-62215 • CVE-2024-30088 • CVE-2024-21338 • Stack Overflow & Arbitrary Overwrite (Kernel) https://0xdbgman.github.io/posts/pwning-the-kernel-windows-internals-driver-exploitation/ #ExploitDevelopment

    Post summary

    The author announced two kernel exploitation write‑ups covering CVE‑2025‑62215, CVE‑2024‑30088, CVE‑2024‑21338 and a stack overflow scenario, providing a link to a detailed blog post that includes exploit code.

    14052615
    350 followersView on X
  • OS Dev@OSdev_
    General

    https://hakaisecurity.io/cve-2024-21338-from-admin-to-kernel-through-token-manipulation-and-windows-kernel-exploitation/research-blog/

    Post summary

    The provided text contains only a URL, offering no explicit details about the vulnerability or its exploitation status.

    00041667
    5.0K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2024-21338-windows #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The article linked in the text announces that CVE‑2024‑21338 for Windows is being actively exploited, though no technical or patch details are provided.

    0001025
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2024-21338 disclosed. CISA: CVE-2024-21338 added to Known Exploited Vulnerabilities — Microsoft Windows Status: ✅ Confirmed exploited in the wild Date added: 2024-03-04 Required action: Apply mitigations per vendor instructions or discontinue use of the…

    Post summary

    CVE-2024-21338 has been confirmed to be exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities list and urging mitigation per vendor instructions.

    1000036
    152 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---

Explore more