CVE-2024-30090High· 7.0▾ MidnightPoC availableMicrosoft Streaming Service Elevation of Privilege Vulnerability
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 38.5 · likelihood 0.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.0%
1 GitHub repo
2.0% → 2.0%
Microsoft Streaming Service Elevation of Privilege Vulnerability
windows_10_1507 < 10.0.10240.20680windows_10_1607 < 10.0.14393.7070windows_10_1809 < 10.0.17763.5936windows_10_21h2 < 10.0.19044.4529windows_10_22h2 < 10.0.19045.4529windows_11_21h2 < 10.0.22000.3019windows_11_22h2 < 10.0.22621.3737windows_11_23h2 < 10.0.22631.3737windows_server_2008windows_server_2008 = r2windows_server_2012windows_server_2012 = r2windows_server_2016 < 10.0.14393.7070windows_server_2019 < 10.0.17763.5936windows_server_2022 < 10.0.20348.2522windows_server_2022_23h2 < 10.0.25398.950Upgrade past the affected range:
windows_10_1507 10.0.10240.20680windows_10_1607 10.0.14393.7070windows_10_1809 10.0.17763.5936windows_10_21h2 10.0.19044.4529windows_10_22h2 10.0.19045.4529windows_11_21h2 10.0.22000.3019windows_11_22h2 10.0.22621.3737windows_11_23h2 10.0.22631.3737windows_server_2016 10.0.14393.7070windows_server_2019 10.0.17763.5936windows_server_2022 10.0.20348.2522windows_server_2022_23h2 10.0.25398.950Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2015-2546High· 8.2The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privile…
CVE-2021-31979High· 7.8Windows Kernel Elevation of Privilege Vulnerability
CVE-2020-0796Critical· 10.0A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
CVE-2024-35250High· 7.8Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2016-7255High· 7.8The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local…
CVE-2022-37969High· 7.8Windows Common Log File System Driver Elevation of Privilege Vulnerability