CISA Known Exploited Vulnerability

CVE-2024-21338 Ransomware

Microsoft · Windows

Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability

Date added
BOD 22-01 due date
CWE CWE-822
Ransomware Known

CISA description

Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.