Buffer Over-read (CWE-126)
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability. This is a buffer over-read vulnerability that could allow an attacker to gain elevated privileges on affected Windows systems. The vulnerability has a CVSS v3.1 base score of 7.8, indicating a high severity.
An attacker who successfully exploits this vulnerability could gain elevated privileges on the affected system. This could allow the attacker to execute arbitrary code with higher privileges, potentially leading to full system compromise. The vulnerability affects confidentiality, integrity, and availability, all rated as HIGH impact. Given that it's a local attack vector with low attack complexity and requires low privileges, it poses a significant risk to system security if exploited.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available. Microsoft has released updates to address this vulnerability. The patch was added on August 13, 2024, and is available through the Microsoft Update Guide.
1. Apply the security updates provided by Microsoft as soon as possible. 2. Prioritize patching for the following affected Windows versions: - Windows Server 2022 23H2 (versions prior to 10.0.25398.1085) - Windows 11 23H2 (versions prior to 10.0.22631.4037) - Windows 11 24H2 (versions prior to 10.0.26100.1457) - Windows 11 22H2 (versions prior to 10.0.22621.4037) 3. Implement the principle of least privilege to minimize the potential impact of exploitation. 4. Monitor systems for suspicious activities, especially attempts to elevate privileges. 5. Keep all Windows systems and software up to date with the latest security patches. 6. Consider restricting access to the Resilient File System (ReFS) where it's not necessary for operations.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Detection for the vulnerability has been added to Qualys (92160)
A CVSS base score of 7.8 has been assigned.
Feedly found the first article mentioning CVE-2024-38135. See article
Feedly estimated the CVSS score as MEDIUM
NVD published the first details for CVE-2024-38135
EPSS Score was set to: 0.05% (Percentile: 19%)