Understanding the New Windows Secure Kernel Mode Elevation of Privilege Vulnerability (CVE-2024-21302)
ID: 5adcbf8d-38fa-5ff4-ad04-456475975504
STIX ID: report--5adcbf8d-38fa-5ff4-ad04-456475975504
Feed Name: Qualys Blog
CVE-2024-21302 is a Windows kernel elevation-of-privilege vulnerability impacting VBS-enabled systems (Windows 10/11, Windows Server 2016+ and certain Azure VM SKUs) that could allow an administrator-level attacker to rollback system files to vulnerable versions and bypass VBS protections; Microsoft has no reports of active exploitation but released mitigation guidance and Qualys provides detection and remediation recommendations including FIM, QID 92154, auditing, credential hygiene, and a Microsoft-signed revocation policy to block outdated VBS files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
