CVE-2024-21305
published 2024-01-09CVE-2024-21305: Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
PriorityP423medium4.4CVSS 3.1
AVLACLPRHUINSUCNIHAN
EPSS
1.51%
71.5th percentile
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1809 | < 10.0.17763.5329 | 10.0.17763.5329 |
| microsoft | windows_10_21h2 | < 10.0.19044.3930 | 10.0.19044.3930 |
| microsoft | windows_10_22h2 | < 10.0.19045.3930 | 10.0.19045.3930 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.5329 | 10.0.17763.5329 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5329 | 10.0.17763.5329 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.3930 | 10.0.19044.3930 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.3930 | 10.0.19045.3930 |
| microsoft | windows_11_21h2 | < 10.0.22000.2713 | 10.0.22000.2713 |
| microsoft | windows_11_22h2 | < 10.0.22621.3007 | 10.0.22621.3007 |
| microsoft | windows_11_23h2 | < 10.0.22631.3007 | 10.0.22631.3007 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.2713 | 10.0.22000.2713 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3007 | 10.0.22621.3007 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3007 | 10.0.22631.3007 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3007 | 10.0.22631.3007 |
| microsoft | windows_server_2019 | < 10.0.17763.5329 | 10.0.17763.5329 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.5329 | 10.0.17763.5329 |
| microsoft | windows_server_2022 | < 10.0.20348.2227 | 10.0.20348.2227 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.2227 | 10.0.20348.2227 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.643 | 10.0.25398.643 |
| msrc | windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
vendor_msrc4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pc6v-rjpx-v6rm: Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
ghsa_unreviewed·2024-01-09
CVE-2024-21305 [MEDIUM] CWE-732 GHSA-pc6v-rjpx-v6rm: Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
Microsoft
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
vendor_msrc·2024-01-09·CVSS 4.4
CVE-2024-21305 [MEDIUM] CWE-732 Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
FAQ: According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to compromise admin credentials on the device.
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
A hypervisor-protected code integrity (HVCI) security feature bypass vulnerability could exist on some specific Microsoft Surface hardware computers that are still in support, when Windows incorrectly allows certain kernel-mode pages to be marked as Read, Write, Execute (RWX) even with HVCI enabled. To exploit this vulnerability an attacker could run a specially crafted application at
No detection rules found.
No public exploits indexed.
Trendmicro
The January 2024 Security Update Review
blogs_trendmicro·2024-01-09·CVSS 8.8
[HIGH] The January 2024 Security Update Review
# The January 2024 Security Update Review
Get the January 2024 security update and review.
By: Dustin Childs
2024/01/09
Read time: ( words)
Save to Folio
Welcome to the first patch Tuesday of 2024. As expected, Microsoft and Adobe have released their latest security patches. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
Adobe Patches for January 2024
For January, Adobe released a single patch addressing six CVEs in Substance 3D Stager. All six bugs are rated Important with the most severe allowing arbitrary code execution.
None of the bugs fixed by Adobe this month are listed as publicly known or under active attack at the time of release. Adobe categorizes t
Trendmicro
The January 2024 Security Update Review
blogs_trendmicro·2024-01-09·CVSS 9.1
[CRITICAL] The January 2024 Security Update Review
## The January 2024 Security Update Review
Get the January 2024 security update and review.
By: Dustin Childs Jan 09, 2024 Read time: ( words)
Save to Folio
Welcome to the first patch Tuesday of 2024. As expected, Microsoft and Adobe have released their latest security patches. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-20700
Windows Hyper-V Remote Code Execution Vulnerability
Critical
7.5
No
No
RCE
CVE-2024-20674
Windows Kerberos Security Feature Bypass Vulnerability
Critical
9
No
No
SFB
CVE-2024-0057
.NET and Visual Studio Framework Security Feature Bypass Vulnerability
Important
Trendmicro
The January 2024 Security Update Review
blogs_trendmicro·2024-01-09·CVSS 9.1
[CRITICAL] The January 2024 Security Update Review
## The January 2024 Security Update Review
Get the January 2024 security update and review.
By: Dustin Childs 2024/01/09 Read time: ( words)
Save to Folio
Welcome to the first patch Tuesday of 2024. As expected, Microsoft and Adobe have released their latest security patches. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-20700
Windows Hyper-V Remote Code Execution Vulnerability
Critical
7.5
No
No
RCE
CVE-2024-20674
Windows Kerberos Security Feature Bypass Vulnerability
Critical
9
No
No
SFB
CVE-2024-0057
.NET and Visual Studio Framework Security Feature Bypass Vulnerability
Important
8
Bleepingcomputer
Microsoft January 2024 Patch Tuesday fixes 49 flaws, 12 RCE bugs
blogs_bleepingcomputer·2024-01-09·CVSS 8.8
[HIGH] Microsoft January 2024 Patch Tuesday fixes 49 flaws, 12 RCE bugs
## Microsoft January 2024 Patch Tuesday fixes 49 flaws, 12 RCE bugs
## Lawrence Abrams
10 Elevation of Privilege Vulnerabilities
7 Security Feature Bypass Vulnerabilities
12 Remote Code Execution Vulnerabilities
11 Information Disclosure Vulnerabilities
6 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
The total count of 49 flaws does not include 4 Microsoft Edge flaws fixed on January 5th.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5034123 cumulative update and Windows 10 KB5034122 update .
## This month's interesting flaws
While there were no actively exploited or publicly disclosed vulnerabilities this month, some flaws are more interesting than others.
Microsoft fixes an Office Remo
Trendmicro
The January 2024 Security Update Review
blogs_trendmicro·2024-01-09·CVSS 9.1
[CRITICAL] The January 2024 Security Update Review
## The January 2024 Security Update Review
Get the January 2024 security update and review.
By: Dustin Childs Jan 09, 2024 Read time: ( words)
Save to Folio
Welcome to the first patch Tuesday of 2024. As expected, Microsoft and Adobe have released their latest security patches. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-20700
Windows Hyper-V Remote Code Execution Vulnerability
Critical
7.5
No
No
RCE
CVE-2024-20674
Windows Kerberos Security Feature Bypass Vulnerability
Critical
9
No
No
SFB
CVE-2024-0057
.NET and Visual Studio Framework Security Feature Bypass Vulnerability
Important
2024-01-09
Published