#VU93907 Integer overflow in Windows Server and Windows - CVE-2024-38080 

 

#VU93907 Integer overflow in Windows Server and Windows - CVE-2024-38080

Published: July 9, 2024 / Updated: September 6, 2024


Vulnerability identifier: #VU93907
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber
CVE-ID: CVE-2024-38080
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Windows Server
Windows
Software vendor:
Microsoft

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to integer overflow in Windows Hyper-V component. A local user can trigger an integer overflow and execute arbitrary code with SYSTEM privileges.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install updates from vendor's website.

External links