CVE-2024-21338

Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability

7.8
CVSS 3.1
59.8 %
EPSS (current)
2024-03-04
KEV addition
Yes
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Microsoft / Windows

Published: 2024-02-13 · Due (CISA): 2024-03-25

CWE: CWE-822 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
exploitdb51946Microsoft Windows 10.0.17763.5458 - Kernel Privilege Escalation2024-04-02
exploitdb52275Microsoft Windows 11 - Kernel Privilege Escalation2025-04-22

References only — no downloads or instructions.

Sources