logo

Microsoft Windows Security Update Advisory (CVE-2024-21338)

ID: adc9faae-3cc4-593a-9949-67bbde7edcfa

STIX ID: report--adc9faae-3cc4-593a-9949-67bbde7edcfa

Feed Name: ASEC

Threat Score
80/100

Date Published: 2024-03-06

Date Updated: 2026-04-26

Author: ASEC

...
...

AhnLab reports on CVE-2024-21338, a high-severity Windows kernel elevation-of-privilege vulnerability in the AppLocker driver (appid.sys) that permits arbitrary kernel memory read/write; the advisory warns that the Lazarus APT has leveraged this flaw via a BYOVD technique to disable security products and escalate privileges, and provides affected Windows builds and Microsoft patch links with guidance to update systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.