Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Windows 10 Version 1809 | 10.0.17763.0 ~ 10.0.17763.5458 | - | |
| Microsoft | Windows 10 Version 1809 | 10.0.0 ~ 10.0.17763.5458 | - | |
| Microsoft | Windows Server 2019 | 10.0.17763.0 ~ 10.0.17763.5458 | - | |
| Microsoft | Windows Server 2019 (Server Core installation) | 10.0.17763.0 ~ 10.0.17763.5458 | - | |
| Microsoft | Windows Server 2022 | 10.0.20348.0 ~ 10.0.20348.2322 | - | |
| Microsoft | Windows 11 version 21H2 | 10.0.0 ~ 10.0.22000.2777 | - | |
| Microsoft | Windows 10 Version 21H2 | 10.0.19043.0 ~ 10.0.19044.4046 | - | |
| Microsoft | Windows 11 version 22H2 | 10.0.22621.0 ~ 10.0.22621.3155 | - | |
| Microsoft | Windows 10 Version 22H2 | 10.0.19045.0 ~ 10.0.19045.4046 | - | |
| Microsoft | Windows 11 version 22H3 | 10.0.22631.0 ~ 10.0.22631.3155 | - | |
| Microsoft | Windows 11 Version 23H2 | 10.0.22631.0 ~ 10.0.22631.3155 | - | |
| Microsoft | Windows Server 2022, 23H2 Edition (Server Core installation) | 10.0.25398.0 ~ 10.0.25398.709 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2024-21338 Windows Kernel Elevation of Privilege Vulnerability | https://github.com/gogobuster/CVE-2024-21338-POC | POC Details |
| 2 | CVE-2024-21338 Windows Kernel Elevation of Privilege Vulnerability Zero-day | https://github.com/crackmapEZec/CVE-2024-21338-POC | POC Details |
| 3 | Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled. | https://github.com/hakaioffsec/CVE-2024-21338 | POC Details |
| 4 | Fork of https://github.com/hakaioffsec/CVE-2024-21338 | https://github.com/UMU618/CVE-2024-21338 | POC Details |
| 5 | PoC for the Untrusted Pointer Dereference in the appid.sys driver | https://github.com/varwara/CVE-2024-21338 | POC Details |
| 6 | Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled. | https://github.com/Zombie-Kaiser/CVE-2024-21338-x64-build- | POC Details |
| 7 | None | https://github.com/tykawaii98/CVE-2024-21338_PoC | POC Details |
| 8 | Windows AppLocker Driver (appid.sys) LPE | https://github.com/Crowdfense/CVE-2024-21338 | POC Details |
| 9 | kcfg bypass example - CVE-2024-21338 | https://github.com/hackyboiz/kcfg-bypass | POC Details |
| 10 | PoC for the Untrusted Pointer Dereference in the appid.sys driver | https://github.com/wusijie/CVE-2024-21338-1 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-21410 | 9.8 CRITICAL | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2024-21401 | 9.8 CRITICAL | Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability |
| CVE-2024-21413 | 9.8 CRITICAL | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2024-21364 | 9.3 CRITICAL | Microsoft Azure Site Recovery Elevation of Privilege Vulnerability |
| CVE-2024-21403 | 9.0 CRITICAL | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerabi |
| CVE-2024-21376 | 9.0 CRITICAL | Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerabil |
| CVE-2024-21349 | 8.8 HIGH | Microsoft ActiveX Data Objects Remote Code Execution Vulnerability |
| CVE-2024-21369 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21359 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21352 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21353 | 8.8 HIGH | Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability |
| CVE-2024-21350 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21372 | 8.8 HIGH | Windows OLE Remote Code Execution Vulnerability |
| CVE-2024-21375 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21420 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21378 | 8.8 HIGH | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2024-21370 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21368 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21367 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21365 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
Showing top 20 of 72 CVEs. View all on vendor page → →
No comments yet