cbcvebase.
CVE-2024-26229
published 2024-04-09

CVE-2024-26229: Windows CSC Service Elevation of Privilege Vulnerability

PriorityP178high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
9.38%
94.9th percentile
Windows CSC Service Elevation of Privilege Vulnerability

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2059610.0.10240.20596
microsoftwindows_10_1607< 10.0.14393.689710.0.14393.6897
microsoftwindows_10_1809< 10.0.17763.569610.0.17763.5696
microsoftwindows_10_21h2< 10.0.19044.429110.0.19044.4291
microsoftwindows_10_22h2< 10.0.19045.429110.0.19045.4291
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2059610.0.10240.20596
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.689710.0.14393.6897
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.569610.0.17763.5696
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.569610.0.17763.5696
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.429110.0.19044.4291
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.429110.0.19045.4291
microsoftwindows_11_21h2< 10.0.22000.289910.0.22000.2899
microsoftwindows_11_22h2< 10.0.22621.344710.0.22621.3447
microsoftwindows_11_23h2< 10.0.22631.344710.0.22631.3447
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.289910.0.22000.2899
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.344710.0.22621.3447
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.344710.0.22631.3447
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.344710.0.22631.3447
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.270676.1.7601.27067
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.226186.0.6003.22618
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.248216.2.9200.24821
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.219246.3.9600.21924
microsoftwindows_server_2016< 10.0.14393.689710.0.14393.6897

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2024-26229 targets the Windows CSC (Client-Side Caching) Service and results in SYSTEM privilege escalation — monitor for unexpected SYSTEM-level process spawning from CSC service context
  • Successful exploitation grants SYSTEM privileges — alert on privilege escalation events where a non-SYSTEM process transitions to SYSTEM via the Windows Kernel / CSC service
  • CVE-2024-26229 is exploited in the wild by Raspberry Robin malware — correlate CSC EoP exploitation attempts with Raspberry Robin indicators (TOR C2 traffic, multi-layer loader activity)
  • ·The exploit status at time of advisory publication was 'Publicly Disclosed: No; Exploited: No; Exploitation Less Likely' — however, Raspberry Robin has since incorporated this CVE, so treat exploitation likelihood as elevated in environments where Raspberry Robin is a threat
  • ·Raspberry Robin deploys a decoy payload when analysis environments are detected, meaning sandbox detonation of samples exploiting CVE-2024-26229 may not reveal the true payload — physical or well-resourced analysis environments are required for accurate behavioral analysis

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.