Improper access control in Microsoft Windows and Windows Server - CVE-2024-26234
Published: April 10, 2024
Vulnerability identifier: #VU88379
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-26234
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper access restrictions within the proxy driver. A local user can execute arbitrary code on the target system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Microsoft Windows
Windows Server
Windows Server
How to mitigate CVE-2024-26234
Install updates from vendor's website.