CVE-2024-38144

Published Aug 13, 2024

Last updated 6 months ago

Overview

Description
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Source
secure@microsoft.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
secure@microsoft.com
CWE-190

Social media

Hype score
Not currently trending
  1. About Elevation of Privilege - #Windows Kernel Streaming WOW Thunk Service Driver (CVE-2024-38144) vulnerability. From Aug 2024 MSPT, but little discussed. Later, #SSD shared a write-up w/ exploit code. Hints it might still be a 0day. #ksthunk ➡️ https://t.co/k6pLWvwB59 https://

    @leonov_av

    13 Jan 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Dell fixes CVE-2024-37143 and CVE-2024-38144 vulnerabilities #Dell #CVE-2024-37143 #CVE-2024-38144 https://t.co/mLnHumaynr

    @pravin_karthik

    16 Dec 2024

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-38144: ksthunk.sys Integer Overflow (PE) https://t.co/yVCXwdhq8S

    @xiosec

    15 Dec 2024

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Top 5 Trending CVEs: 1 - CVE-2024-38144 2 - CVE-2024-41713 3 - CVE-2024-39343 4 - CVE-2024-11667 5 - CVE-2024-49019 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    9 Dec 2024

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Top 5 Trending CVEs: 1 - CVE-2024-38144 2 - CVE-2024-6387 3 - CVE-2020-14938 4 - CVE-2024-7970 5 - CVE-2024-3400 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    8 Dec 2024

    109 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. [하루한줄] CVE-2024-38144 : Windows 11 ksthunk.sys의 Integer Overflow로 인한 LPE 취약점 - hackyboizo https://t.co/q7anICfBnM

    @akaclandestine

    7 Dec 2024

    1151 Impressions

    4 Retweets

    10 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  7. [1day1line] CVE-2024-38144: LPE vulnerability in Windows 11 due to Integer Overflow in ksthunk.sys Local Privilege Escalation in Windows 11 ksthunk.sys due to lack of verification for integers and it leads to Integer Overflow. https://t.co/yTif3j4Y00

    @hackyboiz

    7 Dec 2024

    2979 Impressions

    25 Retweets

    72 Likes

    33 Bookmarks

    0 Replies

    0 Quotes

Configurations