CVE-2024-38193General(microsoft / windows_10_1507)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-09-03. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2windows_11_23h2windows_11_24h2windows_server_2008

2 versions affected across 15 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-13: 1Mentions · 2026-08-15: 1Active Exploitation · 2026-08-15: 108-1308-15
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Classification over time
DateTotalLabels
2026-08-131
General1
2026-08-151
Active Exploitation1
Full discourse2 posts
  • Human Firewall@HumanFirewallHQ
    General

    This is not afd.sys's first time. It's the FOURTH exploited zero-day in that same driver since 2022: CVE-2024-38193 (also Lazarus) CVE-2025-21418 CVE-2025-32709 CVE-2026-68820 (Lazarus, FudModule) One component, nation-state favorite.

    Post summary

    The post lists four past exploited zero‑day CVEs tied to afd.sys, noting the driver’s repeated use as a target but offers no specific technical, patch, or exploit details.

    1000072
    2 followersView on X
  • Joshua Frank@PointFrankRange
    Active Exploitation

    Now pull up: CVE-2025-32709, CVE-2025-21418, CVE-2024-38193. Same driver. Lazarus was on that last one too. That’s four years of a nation-state mining one Windows component.

    Post summary

    The tweet references three CVEs linked to the same Windows driver, noting that Lazarus exploited one of them, indicating sustained nation‑state use over four years.

    0000034
    44 followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---

Explore more