PT-2024-4172 · Microsoft · Windows+1

·

CVE-2024-30088

·

Published

2024-06-11

·

Updated

2026-08-04

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows 10 versions 1809 through 22H2 Windows 11 versions 21H2 through 23H2 Windows Server 2019 Windows Server 2022 Windows Server 2025 Server Core versions prior to February 2025 updates
Description A local privilege escalation issue exists in the Windows Kernel due to a Time-of-Check to Time-of-Use (TOCTOU) race condition and a Use-After-Free flaw in the Windows Kernel Object Manager. The vulnerability is triggered by improper synchronization and reference counting of kernel object handles, specifically within the NtQueryInformationToken() function. An attacker can exploit this by triggering a race condition via repeated token handle operations or using an integer overflow that causes the kernel to allocate an undersized buffer, leading to an out-of-bounds write. This allows a local attacker to corrupt kernel memory, manipulate access tokens, and escalate privileges to NT AUTHORITYSYSTEM, bypassing User Account Control (UAC) and other security boundaries. This flaw has been exploited in the wild by the threat actor OilRig (APT34) in cyber espionage campaigns targeting infrastructure in the UAE and the Gulf region.
Recommendations Update Windows 10, Windows 11, Windows Server 2019, Windows Server 2022, and Windows Server 2025 to Security Update KB5034763 or later cumulative updates. Update Server Core installations to the February 2025 updates or later. Enable Virtualization-Based Security (VBS) and Hypervisor-Protected Code Integrity (HVCI) where supported to harden endpoints.

Exploit

Fix

LPE

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04657
CVE-2024-30088
ZDI-24-606

Affected Products

Exchange Server
Windows