PT-2024-1704 · Microsoft · Windows Defender+8

·

CVE-2024-21338

·

Published

2024-02-13

·

Updated

2026-07-12

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows 10 (affected versions not specified) Windows 11 (affected versions not specified)
Description An elevation of privilege issue exists in the Windows kernel, specifically within the AppLocker driver appid.sys. The flaw stems from an exposed IOCTL (Input/Output Control) with insufficient access control, which allows an attacker with Administrator privileges to cross the boundary into the kernel. By abusing an untrusted pointer exposed through a kernel IOCTL, an attacker can call a user-controlled function pointer in kernel mode. Specifically, the exploit can use ExpProfileDelete() as a target to decrement PreviousMode from 1 to 0, causing NtWriteVirtualMemory() and NtReadVirtualMemory() to bypass security checks. This enables the manipulation of process tokens to obtain full SYSTEM privileges, even on systems with HVCI (Hypervisor-Protected Code Integrity) enabled. This issue has been exploited in the wild as a zero-day by the Lazarus group and has been utilized by the Mallox ransomware family and the BlackCat/ALPHV group.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

LPE

Improper Privilege Management

Untrusted Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01398
CVE-2024-21338

Affected Products

Windows
Windows 10
Windows 11
Windows Applocker
Windows Defender
Windows Kernel
Windows Server 2019
Windows Server 2022
Appid.Sys