---
id: CVE-2024-21338
title: Windows Kernel Elevation of Privilege Vulnerability
summary: Windows Kernel Elevation of Privilege Vulnerability
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-822
vendor: microsoft
product: windows_10_1809
affected:
  - windows_10_1809 < 10.0.17763.5458
  - windows_10_21h2 < 10.0.19044.4046
  - windows_10_22h2 < 10.0.19045.4046
  - windows_11_21h2 < 10.0.22000.2777
  - windows_11_22h2 < 10.0.22621.3155
  - windows_11_23h2 < 10.0.22631.3155
  - windows_server_2019 < 10.0.17763.5458
  - windows_server_2022 < 10.0.20348.2322
  - windows_server_2022_23h2 <= 10.0.25398.709
patched:
  - windows_10_1809 10.0.17763.5458
  - windows_10_21h2 10.0.19044.4046
  - windows_10_22h2 10.0.19045.4046
  - windows_11_21h2 10.0.22000.2777
  - windows_11_22h2 10.0.22621.3155
  - windows_11_23h2 10.0.22631.3155
  - windows_server_2019 10.0.17763.5458
  - windows_server_2022 10.0.20348.2322
published: '2024-02-13'
updated: '2026-07-31'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-21338'
references:
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21338'
    label: secure@microsoft.com
  - url: >-
      https://decoded.avast.io/janvojtesek/lazarus-and-the-fudmodule-rootkit-beyond-byovd-with-an-admin-to-kernel-zero-day/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21338'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://packetstorm.news/files/id/190586/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/52275'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21338
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.5981
epssPercentile: 0.99101
kev: true
kevDateAdded: '2024-03-04'
kevDueDate: '2024-03-25'
kevRansomware: true
exploited: true
exploitAvailable: true
zeroDay: true
ingestedAt: '2026-07-31T04:58:34.503Z'
exploits:
  exploitdb: true
  github: 8
  githubRepos:
    - 'https://github.com/hakaioffsec/CVE-2024-21338'
    - 'https://github.com/UMU618/CVE-2024-21338'
    - 'https://github.com/wusijie/CVE-2024-21338-1'
  checkedAt: '2026-09-26T09:05:30.836Z'
---

## Overview

Windows Kernel Elevation of Privilege Vulnerability

## Affected

- `windows_10_1809 < 10.0.17763.5458`
- `windows_10_21h2 < 10.0.19044.4046`
- `windows_10_22h2 < 10.0.19045.4046`
- `windows_11_21h2 < 10.0.22000.2777`
- `windows_11_22h2 < 10.0.22621.3155`
- `windows_11_23h2 < 10.0.22631.3155`
- `windows_server_2019 < 10.0.17763.5458`
- `windows_server_2022 < 10.0.20348.2322`
- `windows_server_2022_23h2 <= 10.0.25398.709`

## Remediation

Upgrade past the affected range:

- `windows_10_1809 10.0.17763.5458`
- `windows_10_21h2 10.0.19044.4046`
- `windows_10_22h2 10.0.19045.4046`
- `windows_11_21h2 10.0.22000.2777`
- `windows_11_22h2 10.0.22621.3155`
- `windows_11_23h2 10.0.22631.3155`
- `windows_server_2019 10.0.17763.5458`
- `windows_server_2022 10.0.20348.2322`
