PT-2024-4172 · Microsoft · Exchange Server+1
Carrot_C4K3
·
Published
2024-06-11
·
Updated
2026-06-15
·
CVE-2024-30088
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows 10 versions 1809 through 22H2
Windows 11 versions 21H2 through 23H2
Windows Server 2019
Windows Server 2022
Windows Server 2025
Server Core installations prior to February 2025 updates
Description
A local privilege escalation issue exists in the Windows Kernel due to a race condition and improper synchronization in the Object Manager. The flaw is specifically linked to an error in the implementation of the
NtQueryInformationToken() function and an unchecked integer multiplication that leads to an integer overflow. This causes the kernel to allocate a buffer smaller than required, resulting in an out-of-bounds write that allows attackers to corrupt kernel memory and replace process tokens with the SYSTEM token. This can lead to a full bypass of User Account Control (UAC) and security boundaries, enabling the installation of rootkits, bootkits, and credential theft from LSA memory. The issue has been actively exploited by the Iranian threat actor OilRig (APT34) in cyber espionage campaigns targeting infrastructure in the UAE and the Gulf region.Recommendations
Update all affected systems to Security Update KB5034763 or later cumulative updates.
Enable Virtualization-Based Security (VBS) and Hypervisor-Protected Code Integrity (HVCI) where supported to harden endpoints.
Exploit
Fix
LPE
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exchange Server
Windows