Potential Elevation of Privilege Vulnerability in Windows Backup
CVE-2024-38202

7.3HIGH

Key Information:

Vendor
Microsoft
Status
Windows 10 Version 1809
Windows Server 2019
Windows Server 2019 (server Core Installation)
Windows Server 2022
Vendor
CVE Published:
8 August 2024

Badges

💰 Ransomware👾 Exploit Exists📰 News Worthy

Summary

An elevation of privilege vulnerability has been identified within Microsoft Windows Update that allows an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent key features of Virtualization Based Security (VBS). For successful exploitation, an attacker must manipulate an Administrator or a user with delegated permissions into performing a system restore, which inadvertently activates the vulnerability. Microsoft has released a security update to address this concern, made available from October 08, 2024, with specific instructions for updating versions of Windows Recovery Environment (WinRE) as necessary. Further guidance is recommended for users who are unable to immediately apply the update, aimed at reducing the risk and safeguarding their systems.

Affected Version(s)

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.7428

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.6414

Windows 10 Version 21H2 32-bit Systems 10.0.19043.0 < 10.0.19044.5011

News Articles

Researchers Uncover OS Downgrade Vulnerability Targeting Microsoft Windows Kernel

Discover how a new attack technique bypasses Microsoft’s security, enabling OS downgrade attacks on Windows.

2 months ago

Windows Downdate tool lets you 'unpatch' Windows systems

SafeBreach security researcher Alon Leviev has released his Windows Downdate tool, which can be used for downgrade attacks that reintroduce old vulnerabilities in up-to-date Windows 10, Windows 11, and Windows Server systems.

4 months ago

Vulnerability Recap 8/19/24: Microsoft, Ivanti, SolarWinds

Microsoft appears on our list multiple times this week, with notable Patch Tuesday CVEs and an Entra ID vulnerability that affects hybrid clouds.

5 months ago

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 💰

    Used in Ransomware

  • Vulnerability published

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by BleepingComputer

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed9 News Article(s)
.