Record summary

CVE-2024-38080 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2024-38080 in KEV.

Description

Windows Hyper-V Elevation of Privilege Vulnerability

Description source: GitHub Advisory

Exploitation context

Known exploitation

CISA KEV
Listed · Jul 9, 2024 · CISA
VulnCheck KEV
Listed · Jul 9, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 9, 2024 · Source: CVE List

Affected products and versions

7
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE List10.0.22631.0 to < 10.0.22631.3880affected
CVE List10.0.0 to < 10.0.22000.3079affected
CVE List10.0.22621.0 to < 10.0.22621.3880affected
CVE List10.0.22631.0 to < 10.0.22631.3880affected
CVE List10.0.20348.0 to < 10.0.20348.2582affected

Windows Server 2022, 23H2 Edition (Server Core installation)

Browse Microsoft / Windows Server 2022, 23H2 Edition (Server Core installation)
CVE List10.0.25398.0 to < 10.0.25398.1009affected

Proofs of concept

1

Repository PoCs

GitHubpwndorei/CVE-2024-38080Repository PoCby pwndoreiStars: 30Not analyzed6 files

19.6 KiB

GitHub

PoC details

References

3