AI description
CVE-2024-26170 is an elevation of privilege vulnerability affecting the Windows Composite Image File System (CimFS). It stems from a flaw in how CimFS handles certain image files. Successful exploitation of this vulnerability could allow an attacker to gain elevated system privileges.
- Description
- Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability
- Source
- secure@microsoft.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-20
- nvd@nist.gov
- NVD-CWE-noinfo
- Hype score
- Not currently trending
CVE-2024-26170 : Exploiting a Windows Composite Image File System (CimFS) vulnerability https://t.co/QKkTE9zIfk https://t.co/NQjoizh5ez
@elhackernet
16 Apr 2025
584 Impressions
0 Retweets
2 Likes
1 Bookmark
0 Replies
0 Quotes
CVE-2024-26170 : Exploiting a Windows Composite Image File System (CimFS) vulnerability https://t.co/tVvGG1Rkjd https://t.co/DeDUNBgjzk
@freedomhack101
15 Apr 2025
88 Impressions
0 Retweets
2 Likes
2 Bookmarks
0 Replies
0 Quotes
Exploiting a Windows Composite Image File System (CimFS) vulnerability (CVE-2024-26170) https://t.co/RKgbCoKyOX #infosec #windows https://t.co/7Rn8p11ecG
@0xor0ne
15 Apr 2025
6693 Impressions
42 Retweets
174 Likes
46 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2CA95D8E-CAD9-4D07-AE35-36D83D546AA8",
"versionEndExcluding": "10.0.19044.4170"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "968B931A-18E6-4425-B326-5A02C0B93A08",
"versionEndExcluding": "10.0.19045.4170"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D08CEC8B-343C-486E-B6FA-F4D60ACF7E63",
"versionEndExcluding": "10.0.22000.2836"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4DBD4A55-729C-4F86-AE29-6067F62FD03A",
"versionEndExcluding": "10.0.22621.3296"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A332CC68-568F-406B-8463-9FEF359BEA4C",
"versionEndExcluding": "10.0.22631.3296"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9EDA5547-D293-41D0-A10C-4A613E725231",
"versionEndExcluding": "10.0.20348.2340"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0AD05A2D-BA23-4B63-8B75-1395F74C36CB",
"versionEndExcluding": "10.0.25398.763"
}
],
"operator": "OR"
}
]
}
]