CVE-2024-21305

MEDIUM

Windows 10/11, Server 2019-2022 - Hyper-V Code Integrity Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-21305. PoCs published by tandasat.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2024-21305, a vulnerability in Hypervisor-Protected Code Integrity (HVCI) that allows arbitrary kernel-mode code execution by exploiting writable and executable guest physical memory regions. The PoC includes detailed steps to remap memory, inject shellcode, and execute it, bypassing HVCI protections.

Description

Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability

Exploits (1)

nomisec WORKING POC 40 stars
by tandasat · poc
https://github.com/tandasat/CVE-2024-21305

This repository contains a functional proof-of-concept exploit for CVE-2024-21305, a vulnerability in Hypervisor-Protected Code Integrity (HVCI) that allows arbitrary kernel-mode code execution by exploiting writable and executable guest physical memory regions. The PoC includes detailed steps to remap memory, inject shellcode, and execute it, bypassing HVCI protections.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Windows 10.0.22621.1928 with HVCI enabled
Auth required
Prerequisites: Administrator privileges · Intel hardware with VT-d enabled · Ability to perform arbitrary kernel-memory read/write · Test-signing enabled and secure boot disabled
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 4.4
EPSS 0.0149
EPSS Percentile 70.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (9)
microsoft/windows_10_1809 < 10.0.17763.5329
microsoft/windows_10_21h2 < 10.0.19044.3930
microsoft/windows_10_22h2 < 10.0.19045.3930
microsoft/windows_11_21h2 < 10.0.22000.2713
microsoft/windows_11_22h2 < 10.0.22621.3007
microsoft/windows_11_23h2 < 10.0.22631.3007
microsoft/windows_server_2019 < 10.0.17763.5329
microsoft/windows_server_2022 < 10.0.20348.2227
microsoft/windows_server_2022_23h2 < 10.0.25398.643
Published Jan 09, 2024
Tracked Since Feb 18, 2026