logo

CVE-2024-1086 Vulnerability: Critical Privilege Escalation Flaw in Linux Kernel Exploited in the Ransomware Attacks

ID: 9d5cd14b-6c70-57df-8d23-cbb3e8eb422c

STIX ID: report--9d5cd14b-6c70-57df-8d23-cbb3e8eb422c

Feed Name: SOC Prime Blog

Threat Score
80/100

Date Published: 2025-11-04

Date Updated: 2026-04-30

Author: Veronika Telychko

...
...

CISA confirmed active exploitation of CVE-2024-1086, a critical use-after-free in the Linux kernel netfilter (CVSS 7.8) that allows local attackers to escalate to root and has a public PoC; threat actors are leveraging it in ransomware campaigns to disable protections, move laterally, and establish persistence. Organizations are advised to patch affected kernels, apply mitigations such as disabling unprivileged namespace creation (kernel.unprivileged_userns_clone=0), and verify deployment across Linux estates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.