Feed/CVE-2024-21338
CVE-2024-21338HIGHCVSS 7.8CISA KEV: Actively Exploited

Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability

Published Mar 4, 2024·Updated Jul 31, 2026

NVD Description

Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.

Public Exploits & PoCs9 found

[POC] CVE-2024-21338 — CVE-2024-21338-POC

CVE-2024-21338 Windows Kernel Elevation of Privilege Vulnerability Zero-day

3

[POC] CVE-2024-21338 — CVE-2024-21338-x64-build-

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

3

[POC] CVE-2024-21338 — CVE-2024-21338

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

1

[POC] CVE-2024-21338 — CVE-2024-21338

PoC for the Untrusted Pointer Dereference in the appid.sys driver

[POC] CVE-2024-21338 — CVE-2024-21338

Fork of https://github.com/hakaioffsec/CVE-2024-21338

[POC] CVE-2024-21338 — kcfg-bypass

kcfg bypass example - CVE-2024-21338

[POC] CVE-2024-21338 — CVE-2024-21338-POC

CVE-2024-21338 Windows Kernel Elevation of Privilege Vulnerability

[POC] CVE-2024-21338 — CVE-2024-21338

Windows AppLocker Driver (appid.sys) LPE

[POC] CVE-2024-21338 — CVE-2024-21338-1

PoC for the Untrusted Pointer Dereference in the appid.sys driver

Community Discussion

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free