CVE-2024-30088 — Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
CVE-2024-30088: Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Microsoft |
| Product | Windows |
| Date added | 2024-10-15 |
| Due date | 2024-11-05 |
| Ransomware campaign use | Known |
Description
Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.
Required action (CISA)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-30088 ; https://nvd.nist.gov/vuln/detail/CVE-2024-30088
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-30088
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog