Buffer overflow in Microsoft Windows and Windows Server - CVE-2024-21338
Published: February 13, 2024 / Updated: April 1, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the appid.sys AppLocker driver. A local user can trigger memory corruption and execute arbitrary code with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Windows Server
How to mitigate CVE-2024-21338
Links to Public Exploits and PoC-codes
- Exploit #12536 - CVE-2024-21338-Exploit (April 1, 2026)
- Exploit #10652 - Microsoft Windows 10.0.17763.5458 - Kernel Privilege Escalation (October 25, 2024)
- Exploit #10266 - CVE-2024-21338 (August 2, 2024)
- Exploit #10167 - CVE-2024-21338_PoC (July 5, 2024)
- Exploit #9986 - CVE-2024-21338 (June 14, 2024)
- Exploit #9709 - CVE-2024-21338 (April 19, 2024)