logo

Microsoft waited 6 months to patch actively exploited admin-to-kernel vulnerability

ID: c3db98b9-db54-54bd-be70-1ad1425ec86f

STIX ID: report--c3db98b9-db54-54bd-be70-1ad1425ec86f

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-03-11

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

Security researchers allege Lazarus Group exploited an admin-to-kernel zero-day in appid.sys to install the FudModule rootkit, achieving kernel read/write and persisting for months while Microsoft delayed patching CVE-2024-21338; the bulletin also highlights multiple other critical vulnerabilities (including actively exploited iOS CVEs) and broader security advisories and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.