CVE-2024-38014
published 2024-09-10CVE-2024-38014: Windows Installer Elevation of Privilege Vulnerability
PriorityP181high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-10-01
Exploited in the wild
EPSS
6.01%
92.5th percentile
Windows Installer Elevation of Privilege Vulnerability
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20766 | 10.0.10240.20766 |
| microsoft | windows_10_1607 | < 10.0.14393.7336 | 10.0.14393.7336 |
| microsoft | windows_10_1809 | < 10.0.17763.6293 | 10.0.17763.6293 |
| microsoft | windows_10_21h2 | < 10.0.19044.4894 | 10.0.19044.4894 |
| microsoft | windows_10_22h2 | < 10.0.19045.4894 | 10.0.19045.4894 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20766 | 10.0.10240.20766 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.7336 | 10.0.14393.7336 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.6293 | 10.0.17763.6293 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.4894 | 10.0.19044.4894 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4894 | 10.0.19045.4894 |
| microsoft | windows_11_21h2 | < 10.0.22000.3197 | 10.0.22000.3197 |
| microsoft | windows_11_22h2 | < 10.0.22621.4169 | 10.0.22621.4169 |
| microsoft | windows_11_23h2 | < 10.0.22631.4169 | 10.0.22631.4169 |
| microsoft | windows_11_24h2 | < 10.0.26100.1742 | 10.0.26100.1742 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.3197 | 10.0.22000.3197 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.4169 | 10.0.22621.4169 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.4169 | 10.0.22631.4169 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.4169 | 10.0.22631.4169 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.1742 | 10.0.26100.1742 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27320 | 6.1.7601.27320 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.22870 | 6.0.6003.22870 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25073 | 6.2.9200.25073 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22175 | 6.3.9600.22175 |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploitation of this vulnerability results in SYSTEM privilege gain — alert on privilege escalation events where a non-SYSTEM process elevates to SYSTEM via Windows Installer (msiexec.exe) ↗
- →CISA KEV listed with remediation due date 2024-10-01 — treat any unpatched Windows system as actively at risk; monitor for improper privilege management events in Windows Installer ↗
- →Prioritize patching as part of Microsoft's September 2024 Patch Tuesday — CVE-2024-38014 was highlighted as a priority alongside CVE-2024-43491 ↗
- ·Exploit status is confirmed as actively exploited (Exploitation Detected) but NOT publicly disclosed — no public PoC or write-up is available for this specific CVE, unlike CVE-2024-38217 which had public exploit code on GitHub ↗
- ·Affected component is Windows Installer across multiple Windows versions — patches are delivered via multiple KB articles (e.g., KB5043050, KB5042881, KB5043067, KB5043064, KB5043076, KB5043080, KB5043083, KB5043051, KB5043135, KB5043087, KB5043125, KB5043138); verify patch applicability per OS version ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Installer Elevation of Privilege Vulnerability
vendor_msrc·2024-09-10·CVSS 7.8
CVE-2024-38014 [HIGH] CWE-269 Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table?
The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerabilities that affect their machine and to install the updates if they are not receiving automatic updates. Note that the general availability date for Windows 11, version 24H2 is scheduled for later this year.
Windows Installer: Windows Instal
CISA
Microsoft Windows Installer Improper Privilege Management Vulnerability
cisa·2024-09-10·CVSS 7.8
CVE-2024-38014 [HIGH] CWE-269 Microsoft Windows Installer Improper Privilege Management Vulnerability
Vulnerability: Microsoft Windows Installer Improper Privilege Management Vulnerability
Affected: Microsoft Windows
Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38014; https://nvd.nist.gov/vuln/detail/CVE-2024-38014
Remediation Due Date: 2024-10-01
GHSA
GHSA-mvx5-3q3c-pr6w: Windows Installer Elevation of Privilege Vulnerability
ghsa_unreviewed·2024-09-10
CVE-2024-38014 [HIGH] CWE-269 GHSA-mvx5-3q3c-pr6w: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
VulnCheck
Microsoft Windows Installer Improper Privilege Management Vulnerability
vulncheck·2024·CVSS 7.8
CVE-2024-38014 [HIGH] CWE-269 Microsoft Windows Installer Improper Privilege Management Vulnerability
Microsoft Windows Installer Improper Privilege Management Vulnerability
Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2024-Sep; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38014; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.zerodayinitiative.com/blog/2024/9/10/the-september-2024-security-update-review; https://www.ptsecurity.com/ru-ru/research/analytics/dajdzhest-trendovyh-uyazvimostej-sentyabr-2024-goda
No detection rules found.
No public exploits indexed.
Checkpoint
16th September – Threat Intelligence Report
blogs_checkpoint·2024-09-16
CVE-2024-43491 16th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 16th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 16th September, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The Port of Seattle has confirmed that the Rhysida ransomware group was responsible for a cyberattack in August 2024, which affected its critical systems, including Seattle-Tacoma International Airport. The ransomware attack caused major service disruptions, including outages in check-in systems, baggage handling, and
Bleepingcomputer
Microsoft September 2024 Patch Tuesday fixes 4 zero-days, 79 flaws
blogs_bleepingcomputer·2024-09-10·CVSS 7.8
[HIGH] Microsoft September 2024 Patch Tuesday fixes 4 zero-days, 79 flaws
## Microsoft September 2024 Patch Tuesday fixes 4 zero-days, 79 flaws
## Lawrence Abrams
30 Elevation of Privilege Vulnerabilities
4 Security Feature Bypass Vulnerabilities
23 Remote Code Execution Vulnerabilities
11 Information Disclosure Vulnerabilities
8 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5043076 cumulative update and Windows 10 KB5043064 update .
## Four zero-days disclosed
This month's Patch Tuesday fixes three actively exploited, one of which was publicly disclosed, and another that reintroduces old CVEs so is marked as exploited.
Microsoft classifies a zero-day flaw as one that is publicly disclosed or actively exploited whil
Krebs
Bug Left Some Windows PCs Dangerously Unpatched
blogs_krebs·2024-09-10·CVSS 7.3
CVE-2024-43491 [HIGH] Bug Left Some Windows PCs Dangerously Unpatched
Microsoft Corp. today released updates to fix at least 79 security vulnerabilities in its Windows operating systems and related software, including multiple flaws that are already showing up in active attacks. Microsoft also corrected a critical bug that has caused some Windows 10 PCs to remain dangerously unpatched against actively exploited vulnerabilities for several months this year.
By far the most curious security weakness Microsoft disclosed today has the snappy name of CVE-2024-43491 , which Microsoft says is a vulnerability that led to the rolling back of fixes for some vulnerabilities affecting “optional components” on certain Windows 10 systems produced in 2015. Those include Windows 10 systems that installed the monthly security update for Windows released in March 2024, or ot
Trendmicro
The September 2024 Security Update Review
blogs_trendmicro·2024-09-10
The September 2024 Security Update Review
# The September 2024 Security Update Review
Get the September 2023 security update and review.
By: Zero Day Initiative
2024/09/10
Read time: ( words)
Save to Folio
We’ve reached September and the pumpkin spice floats in the air. While they aren’t pumpkin-spiced, Microsoft and Adobe have released their latest spicy security patches – including some zesty 0-days. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for September 2024
For September, Adobe released eight bulletins covering 28 CVEs in Adobe Acrobat and Reader, ColdFusion, Photoshop, Media Encoder, Audition, After Effects, Premier Pro, and Illustrator.
Qualys
Microsoft and Adobe Patch Tuesday, September 2024 Security Update Review
blogs_qualys·2024-09-10
Microsoft and Adobe Patch Tuesday, September 2024 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for September 2024
Adobe Patches for September 2024
Zero-day Vulnerabilities Patched in September Patch Tuesday Edition
Critical Severity Vulnerabilities Patched in September Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Qualys Monthly Webinar Series
Microsoft’s September Patch Tuesday updates are out, addressing a range of vulnerabilities across multiple products. Let’s dive into the key updates and their implications.
## Microsoft Patch Tuesday for September 2024
Microsoft Patch’s Tuesday, September 2024 edition addressed 79 vulnerabilities, including s
Talos
Four zero-days included in group of 79 vulnerabilities Microsoft discloses, including one with 9.8 severity score
blogs_talos·2024-09-10·CVSS 7.8
CVE-2024-38226 [HIGH] Four zero-days included in group of 79 vulnerabilities Microsoft discloses, including one with 9.8 severity score
Microsoft disclosed four vulnerabilities that are actively being exploited in the wild as part of its regular Patch Tuesday security update this week in what’s become a regular occurrence for the company’s patches in 2024.
Two of the zero-day vulnerabilities, CVE-2024-38226 and CVE-2024-38014, exist in the Microsoft Publisher software and Windows Installer, respectively. Last month, Microsoft disclosed six vulnerabilities in its Patch Tuesday that were already being exploited in the wild.
In all, September’s monthly round of patches from Microsoft included 79 vulnerabilities, seven of which are considered critical. In addition to the zero-days disclosed Tuesday, Microsoft also fixed a security issue that had already been publicly disclosed: CVE-2024-38217, a vulnerability in Windows Mark
Qualys
Microsoft & Adobe September 2024 Security Update Review | Qualys
blogs_qualys·2024-09-10
Microsoft & Adobe September 2024 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for September 2024
- Adobe Patches for September 2024
- Zero-day Vulnerabilities Patched in September Patch Tuesday Edition
- Critical Severity Vulnerabilities Patched in September Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- Qualys Monthly Webinar Series
Microsoft’s September Patch Tuesday updates are out, addressing a range of vulnerabilities across multiple products. Let’s dive into the key updates and their implications.
## Microsoft Patch Tuesday for September 2024
Microsoft Patch’s Tuesday, September 2024 edition addressed 79 vulnerabilities,
Krebs
Bug Left Some Windows PCs Dangerously Unpatched
blogs_krebs·2024-09-10·CVSS 7.3
CVE-2024-43491 [HIGH] Bug Left Some Windows PCs Dangerously Unpatched
Microsoft Corp. today released updates to fix at least 79 security vulnerabilities in its Windows operating systems and related software, including multiple flaws that are already showing up in active attacks. Microsoft also corrected a critical bug that has caused some Windows 10 PCs to remain dangerously unpatched against actively exploited vulnerabilities for several months this year.
By far the most curious security weakness Microsoft disclosed today has the snappy name of CVE-2024-43491, which Microsoft says is a vulnerability that led to the rolling back of fixes for some vulnerabilities affecting “optional components” on certain Windows 10 systems produced in 2015. Those include Windows 10 systems that installed the monthly security update for Windows released in March 2024, or oth
Talos
Four zero-days included in group of 79 vulnerabilities Microsoft discloses, including one with 9.8 severity score
blogs_talos·2024-09-10·CVSS 7.8
CVE-2024-38226 [HIGH] Four zero-days included in group of 79 vulnerabilities Microsoft discloses, including one with 9.8 severity score
## Four zero-days included in group of 79 vulnerabilities Microsoft discloses, including one with 9.8 severity score
Microsoft disclosed four vulnerabilities that are actively being exploited in the wild as part of its regular Patch Tuesday security update this week in what’s become a regular occurrence for the company’s patches in 2024.
Two of the zero-day vulnerabilities, CVE-2024-38226 and CVE-2024-38014, exist in the Microsoft Publisher software and Windows Installer, respectively. Last month, Microsoft disclosed six vulnerabilities in its Patch Tuesday that were already being exploited in the wild.
In all, September’s monthly round of patches from Microsoft included 79 vulnerabilities, seven of which are considered critical. In addition to the zero-days disclosed Tuesday, Microsoft
Trendmicro
The September 2024 Security Update Review
blogs_trendmicro·2024-09-10·CVSS 7.8
[HIGH] The September 2024 Security Update Review
## The September 2024 Security Update Review
Get the September 2023 security update and review.
By: Zero Day Initiative 2024/09/10 Read time: ( words)
Save to Folio
We’ve reached September and the pumpkin spice floats in the air. While they aren’t pumpkin-spiced, Microsoft and Adobe have released their latest spicy security patches – including some zesty 0-days. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
CVE
Title
Severity
CVSS
Public
Exploited
XI
Type
CVE-2024-38217
Windows Mark of the Web Security Feature Bypass Vulnerability
Important
5.4
Yes
Yes
0
SFB
CVE-2024-43491 †
Microsoft Windows Update Remote
Tenable
Microsoft’s September 2024 Patch Tuesday Addresses 79 CVEs (CVE-2024-43491)
blogs_tenable·2024-09-10·CVSS 9.8
[CRITICAL] Microsoft’s September 2024 Patch Tuesday Addresses 79 CVEs (CVE-2024-43491)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Crowdstrike
September 2024 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] September 2024 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2024-09-10
Published
2024-09-10
Added to CISA KEV
Exploited in the wild