CVE-2024-26229

HIGH EXPLOITED

Microsoft Windows 10 1507 < 10.0.10240.20596 - Heap Buffer Overflow

Title source: rule

Description

Windows CSC Service Elevation of Privilege Vulnerability

Exploits (10)

nomisec WORKING POC 140 stars
by RalfHacker · local
https://github.com/RalfHacker/CVE-2024-26229-exploit
nomisec WORKING POC 40 stars
by Cracked5pider · local
https://github.com/Cracked5pider/eop24-26229
nomisec WORKING POC 27 stars
by apkc · local
https://github.com/apkc/CVE-2024-26229-BOF
nomisec WRITEUP 12 stars
by team-MineDEV · poc
https://github.com/team-MineDEV/CVE-2024-26229
nomisec WORKING POC
by 0xGunrunner · local
https://github.com/0xGunrunner/CVE-2024-26229-BOF
nomisec WORKING POC
by vettrivel007 · client-side
https://github.com/vettrivel007/CVE-2024-26229
nomisec STUB
by mqxmm · poc
https://github.com/mqxmm/CVE-2024-26229
nomisec WORKING POC
by dkstar11q · poc
https://github.com/dkstar11q/CVE-2024-26229-lpe

Scores

CVSS v3 7.8
EPSS 0.8338
EPSS Percentile 99.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-11-19
CWE
CWE-122
Status published
Products (15)
microsoft/windows_10_1507 < 10.0.10240.20596 (2 CPE variants)
microsoft/windows_10_1607 < 10.0.14393.6897 (2 CPE variants)
microsoft/windows_10_1809 < 10.0.17763.5696
microsoft/windows_10_21h2 < 10.0.19044.4291
microsoft/windows_10_22h2 < 10.0.19045.4291
microsoft/windows_11_21h2 < 10.0.22000.2899
microsoft/windows_11_22h2 < 10.0.22621.3447
microsoft/windows_11_23h2 < 10.0.22631.3447
microsoft/windows_server_2008
microsoft/windows_server_2008 r2 sp1
... and 5 more
Published Apr 09, 2024
Tracked Since Feb 18, 2026