CVE-2024-51324Active Exploitation

LOWCVSS 3.8 · LOW

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-18); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-18: 1Mentions · 2026-08-29: 1Active Exploitation · 2026-08-18: 1Technical Details · 2026-08-18: 108-1808-29
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-181
Active Exploitation1
2026-08-291
General1
Full discourse2 posts
  • Voidwalker@JustWantToQ1
    General

    That driver.sys file is CVE-2024-51324

    Post summary

    The text only identifies a driver.sys file as CVE-2024-51324 without providing additional details or context.

    00020136
    3.2K followersView on X
  • Proven Data@Proven_Data
    Active Exploitation

    DeadLock ransomware exploits CVE-2024-51324 to kill EDR from kernel mode, encrypting after a 5-day dwell. No public decryptor exists. https://www.provendata.com/blog/deadlock-ransomware #CyberSecurity #InfoSec #Ransomware #DFIR #IncidentResponse

    Post summary

    DeadLock ransomware actively exploits CVE‑2024‑51324 to disable EDR from kernel mode, holding victim data in encryption for up to five days; no public decryptor exists.

    0000080
    904 followersView on X

Explore more