CVE-2024-6769

MEDIUM

Microsoft Windows <2022 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-6769. PoCs published by fortra.

AI-analyzed exploit summary This repository contains a working PoC for CVE-2024-6769, which chains a DLL hijacking vulnerability via drive remapping with an activation cache poisoning bug in CSRSS to escalate from medium to high integrity and achieve full administrator privileges.

Description

A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process to a high integrity process without the intervention of a UAC prompt.

Exploits (1)

nomisec WORKING POC 79 stars
by fortra · poc
https://github.com/fortra/CVE-2024-6769

This repository contains a working PoC for CVE-2024-6769, which chains a DLL hijacking vulnerability via drive remapping with an activation cache poisoning bug in CSRSS to escalate from medium to high integrity and achieve full administrator privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Windows 10, Windows 11, Windows Server 2019, Windows Server 2022
Auth required
Prerequisites: Medium integrity process · User must be part of the Administrators group · Ability to remap the root drive · Ability to place a malicious DLL in a controlled directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 6.7
EPSS 0.0107
EPSS Percentile 60.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-426 CWE-427
Status published
Products (5)
Microsoft/Windows 10 10.0.0
Microsoft/Windows 11 10.0.0
Microsoft/Windows Server 2016 10.0.0
Microsoft/Windows Server 2019 10.0.0
Microsoft/Windows Server 2022 10.0.0
Published Sep 26, 2024
Tracked Since Feb 18, 2026