CVE-2024-30088Active Exploitation(microsoft / windows_10_1507)

CRITICALCVSS 7.0 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Windows Kernel Elevation of Privilege Vulnerability

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-11-05. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-367

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Peaked at 3 mentions on most recent observed day (2026-07-07)
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2windows_11_23h2windows_server_2016windows_server_2019

Deep dive

Activity timeline8 mentions / 6d
01223Mentions · 2026-01-29: 1Mentions · 2026-02-04: 1Mentions · 2026-02-15: 1Mentions · 2026-04-04: 1Mentions · 2026-06-12: 1Mentions · 2026-07-07: 3PoC Mentioned / Linked · 2026-02-04: 1PoC Mentioned / Linked · 2026-02-15: 1PoC Mentioned / Linked · 2026-06-12: 1PoC Mentioned / Linked · 2026-07-07: 2Exploit Tool / Code · 2026-06-12: 1Active Exploitation · 2026-01-29: 1Active Exploitation · 2026-07-07: 2Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-04: 1Technical Details · 2026-06-12: 1Technical Details · 2026-07-07: 201-2902-0402-1504-0406-1207-07
Signal classification4 categories
Active Exploitation
337.5%
PoC
337.5%
Patch
112.5%
Disclosure
112.5%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-291
Active Exploitation1
2026-02-041
Patch1
2026-02-151
PoC1
2026-04-041
Disclosure1
2026-06-121
PoC1
2026-07-073
Active Exploitation2PoC1
Full discourse8 posts
  • OS Dev@OSdev_
    Active Exploitation

    CVE-2024-30088 is a Windows kernel privilege escalation vulnerability caused by a Time-of-Check to Time-of-Use (TOCTOU) race condition. The vulnerability exists at the boundary between user-mode and kernel-mode memory. A user-controlled buffer is validated by the kernel, but its contents can change before the kernel actually writes to it. By winning this race, an attacker can redirect privileged kernel writes, leading to memory corruption and ultimately SYSTEM privileges. According to public analysis, the flaw was exploited in the wild by APT34 (OilRig), making it another reminder that race conditions can be just as powerful as classic memory corruption bugs. It's an excellent case study in TOCTOU vulnerabilities, kernel/user memory boundaries, synchronization, and secure pointer validation.

    Post summary

    CVE‑2024‑30088 is a Windows kernel TOCTOU race that allows SYSTEM privilege escalation, and it has been proven to be exploited in the wild by APT34 (OilRig).

    4151107365.2K
    5.0K followersView on X
  • 0xdf@0xdf_
    Disclosure

    DarkZero from @hackthebox_eu features cross-forest MSSQL linked servers, four privesc paths (token theft, ADCS/RunAsCS, NTLM reflection via CMTI, CVE-2024-30088), and cross-forest TGT delegation for domain takeover. https://0xdf.gitlab.io/2026/04/04/htb-darkzero.html

    Post summary

    The tweet announces that the DarkZero HackTheBox machine includes CVE‑2024‑30088 and other privilege‑escalation vectors, but offers no proof‑of‑concept, exploit code, or patch information.

    216083283.7K
    26.5K followersView on X
  • OS Dev@OSdev_
    PoC

    One unchecked integer multiplication can own the entire Windows kernel. In CVE-2024-30088, an integer overflow caused the kernel to allocate a smaller buffer than required while continuing to process it as if it were large enough. The resulting out-of-bounds write let attackers corrupt kernel memory, build arbitrary read/write primitives, and ultimately replace their process token with the SYSTEM token. https://github.com/tykawaii98/CVE-2024-30088

    Post summary

    The post discloses CVE‑2024‑30088, an integer overflow that leads to kernel memory corruption and privilege escalation, and provides a proof‑of‑concept via a linked GitHub repository.

    014071414.6K
    4.7K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    以下の4脆弱性がランサムウェアに悪用されたことが確認された。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログが更新。 - Windowsの権限昇格CVE-2024-49039, CVE-2024-30088 - CyberPanelの無認証root権限RCE CVE-2024-51567 - FirefoxのRCE CVE-2024-9680 https://t.co/rE32uwR7pJ

    Post summary

    The tweet confirms that four CVEs were exploited by ransomware, as noted in CISA's updated exploited vulnerability catalog.

    06038163.4K
    7.2K followersView on X
  • DbgMan ^_^@0XDbgMan
    PoC

    Dropped 2 Writeups Windows & Driver Internals → Exploitation Kernel Exploit ( CVEs + Root Cause → Exploit) • CVE-2025-62215 • CVE-2024-30088 • CVE-2024-21338 • Stack Overflow & Arbitrary Overwrite (Kernel) https://0xdbgman.github.io/posts/pwning-the-kernel-windows-internals-driver-exploitation/ #ExploitDevelopment

    Post summary

    The post references two writeups that provide proof‑of‑concepts for kernel exploitation of CVE-2025-62215, CVE-2024-30088, and CVE-2024-21338, linking to a blog article, but it does not detail exploit code, patches, or active attacks.

    14052615
    350 followersView on X
  • OS Dev@OSdev_
    Active Exploitation

    https://medium.com/@shira.borochovich/cve-2024-30088-kernel-level-toctou-vulnerability-abused-by-apt34-for-privilege-escalation-in-5a75035bf076

    Post summary

    The Medium article reports a kernel‑level TOCTOU flaw (CVE‑2024‑30088) actively abused by APT34 for privilege escalation, provides technical details and patch information, confirming real‑world exploitation.

    00031377
    5.0K followersView on X
  • OS Dev@OSdev_
    PoC

    https://github.com/tykawaii98/CVE-2024-30088

    Post summary

    The provided link to a GitHub repository suggests it hosts a proof‑of‑concept for CVE‑2024‑30088, while the text lacks details on exploitation, patches, or technical attributes.

    00021324
    5.0K followersView on X
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2024-30088: Windows Kernel Local Privilege Escalation Alert 🚨 Microsoft Windows A local privilege escalation vulnerability has been disclosed in the Windows Kernel, allowing any local code execution to escalate privileges to NT AUTHORITY\SYSTEM. A public proof of concept is available, making this a high-risk post-exploitation primitive. Risk Severity: Critical. CVSS 7.0. Public proof of concept available. Reliable local privilege escalation on a massively deployed target. Impact: Unauthenticated local privilege escalation to SYSTEM. Full bypass of UAC and Windows security boundaries. Kernel-level compromise enabling rootkits and bootkits. Credential theft from LSA memory. Accelerated ransomware deployment and lateral movement. Root Cause: CWE-416, Use-After-Free in the Windows Kernel Object Manager. Improper synchronization and reference counting of kernel object handles. A race condition allows stale pointers to freed token objects to be reused and corrupted. Attackers can: Trigger a race condition via repeated token handle operations. Corrupt kernel memory and manipulate access tokens. Enable privileged rights such as SeDebugPrivilege. Impersonate SYSTEM and gain unrestricted control of the host. Are You Affected? Vulnerable systems include Windows 10 versions 1809 through 22H2, Windows 11 versions 21H2 through 23H2, Windows Server 2019, 2022, and 2025, and Server Core installations prior to February 2025 updates. Patched systems include all hosts with the February 2025 Security Update KB5034763 or later cumulative updates. Immediate Action Required: Update all systems to KB5034763 or later immediately. Harden endpoints by enabling VBS and HVCI where supported. Hunt for unexpected SYSTEM-level processes and abnormal privilege use. Respond by isolating suspected systems, capturing memory dumps, and rotating all credentials. Kernel privilege escalations are ransomware force multipliers. Patch fast, or assume SYSTEM is already lost. 🛡️ #ostorlabCVE

    Post summary

    CVE‑2024‑30088 is a critical Windows Kernel local privilege escalation with a publicly available PoC; Microsoft has issued patch KB5034763 to fix the issue and advises immediate remediation.

    00000113
    582 followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---

Explore more