CVE/vulnerability

PoC Exploit Released For 0-Day Windows Kernel Privilege Escalation Vulnerability

Microsoft released several patches for multiple vulnerabilities during the Patch Tuesday for August 2024. One of the vulnerabilities listed by Microsoft was the CVE-2024-38106.

This vulnerability is associated with Windows Kernel Privilege Escalation affecting multiple Microsoft Windows OSes including Windows 10, 11 and Windows Server (2016, 2019, 2022). 

Moreover, Microsoft stated that this vulnerability was actively exploited by threat actors.

As a matter of fact, Microsoft also mentioned that no user interaction was required for exploiting this vulnerability.

The severity for this vulnerability was given as 7.0 (High).

Technical Analysis – CVE-2024-38106

According to the reports shared with Cyber Security News, CVE-2024-38106 was linked to a race condition.

Successful exploitation of this vulnerability could lead to the threat actor gaining SYSTEM level privileges on the affected system.

Are You From SOC/DFIR Teams? - Try Advanced Malware and Phishing Analysis With ANY.RUN - 14 day free trial

Further, it was stated that the vulnerability was a little complex to exploit.

Researchers at Pixiepoint investigated the patch for this vulnerability. It was revealed that the fix was made on the ntoskrnl.exe that was also responsible for several other bugs fixed by Microsoft.

On analyzing further, there were two security changes made to the functions VslGetSetSecureContext() and NtSetInformationWorkerFactory().

Fix analysis (Source: Pixiepoint)

VslGetSetSecureContext() was implemented with a fix to mitigate a race condition. This was done by making the function properly lock the VslpEnterIumSecureMode() operation that was related to the VBS secure kernel.

NtSetInformationWorkerFactory() was implemented with a similar fix for mitigating a race condition.

However, here it was done by adding a flag inside NtShutdownWorkerFactory() –> ExpShutdownWorkerFactory():

However, the proof of concept code can be found below. As per the proof of concept, it triggers calling the NtClose() on worker factory object handles to achieve a vulnerable state.

This will result in reaching KiInsertTimer2WithCollectionLockHeld() worker factory object and freeing the associated timer.

Organizations should apply the necessary patches to vulnerable products to prevent them from being exploited.

What Does MITRE ATT&CK Expose About Your Enterprise Security? - Watch Free Webinar!

Eswar

Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Recent Posts

Google Announces Vanir, A Open-Source Security Patch Validation Tool

Google has officially launched Vanir, an open-source security patch validation tool designed to streamline and automate…

14 hours ago

New Transaction-Relay Jamming Vulnerability Let Attackers Exploits Bitcoin Nodes

A newly disclosed transaction-relay jamming vulnerability has raised concerns about the security of Bitcoin nodes,…

16 hours ago

Raspberry Pi 500 & Monitor, Complete Desktop Setup at $190

Raspberry Pi, a pioneer in affordable and programmable computing, has once again elevated its game…

16 hours ago

Qlik Sense for Windows Vulnerability Allows Remote Code Execution

Qlik has identified critical vulnerabilities in its Qlik Sense Enterprise for Windows software that could…

18 hours ago

QNAP High Severity Vulnerabilities Let Remote attackers to Compromise System

QNAP Systems, Inc. has identified multiple high-severity vulnerabilities in its operating systems, potentially allowing attackers…

20 hours ago

Healthcare Security Strategies for 2025

Imagine this: It's a typical Tuesday morning in a bustling hospital. Doctors make their rounds,…

21 hours ago