logo

Understanding the New Windows Secure Kernel Mode Elevation of Privilege Vulnerability (CVE-2024-21302)

ID: 5adcbf8d-38fa-5ff4-ad04-456475975504

STIX ID: report--5adcbf8d-38fa-5ff4-ad04-456475975504

Feed Name: Qualys Blog

Threat Score
55/100

Date Published: 2024-08-13

Date Updated: 2026-04-28

Author: Palmer Wallace

...
...

CVE-2024-21302 is a Windows kernel elevation-of-privilege vulnerability impacting VBS-enabled systems (Windows 10/11, Windows Server 2016+ and certain Azure VM SKUs) that could allow an administrator-level attacker to rollback system files to vulnerable versions and bypass VBS protections; Microsoft has no reports of active exploitation but released mitigation guidance and Qualys provides detection and remediation recommendations including FIM, QID 92154, auditing, credential hygiene, and a Microsoft-signed revocation policy to block outdated VBS files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.