CVE-2024-38028
published 2024-07-09CVE-2024-38028: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
PriorityP346high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.07%
79.3th percentile
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20710 | 10.0.10240.20710 |
| microsoft | windows_10_1607 | < 10.0.14393.7159 | 10.0.14393.7159 |
| microsoft | windows_10_1809 | < 10.0.17763.6054 | 10.0.17763.6054 |
| microsoft | windows_10_21h2 | < 10.0.19044.4651 | 10.0.19044.4651 |
| microsoft | windows_10_22h2 | < 10.0.19045.4651 | 10.0.19045.4651 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20710 | 10.0.10240.20710 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.7159 | 10.0.14393.7159 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.6054 | 10.0.17763.6054 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.4651 | 10.0.19044.4651 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4651 | 10.0.19045.4651 |
| microsoft | windows_11_21h2 | < 10.0.22000.3079 | 10.0.22000.3079 |
| microsoft | windows_11_22h2 | < 10.0.22621.3880 | 10.0.22621.3880 |
| microsoft | windows_11_23h2 | < 10.0.22631.3880 | 10.0.22631.3880 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.3079 | 10.0.22000.3079 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3880 | 10.0.22621.3880 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3880 | 10.0.22631.3880 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3880 | 10.0.22631.3880 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27219 | 6.1.7601.27219 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.22769 | 6.0.6003.22769 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.24975 | 6.2.9200.24975 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22074 | 6.3.9600.22074 |
| microsoft | windows_server_2016 | < 10.0.14393.7159 | 10.0.14393.7159 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.7159 | 10.0.14393.7159 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cisa7.8HIGH
vendor_msrc7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x48j-rv4g-x2hh: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
ghsa_unreviewed·2024-07-09
CVE-2024-38028 [HIGH] CWE-125 GHSA-x48j-rv4g-x2hh: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Microsoft
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
vendor_msrc·2024-07-09·CVSS 7.2
CVE-2024-38028 [HIGH] CWE-125 Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
To exploit this vulnerability, a victim machine must be running a performance counter collection tool such as Performance Monitor to collect performance counter data from an attacker machine.
An attacker with local admin authority on the attacker machine could run malicious code remotely in the victim machine's performance counter data collector process.
Windows Performance Monitor: Windows Performance Monitor
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/S
CISA
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
cisa·2024-04-23·CVSS 7.8
CVE-2022-38028 [HIGH] Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-38028; https://nvd.nist.gov/vuln/detail/CVE-2022-38028
Remediation Due Date: 2024-05-14
No public exploits indexed.
Trendmicro
The July 2024 Security Update Review
blogs_trendmicro·2024-07-09
The July 2024 Security Update Review
## The July 2024 Security Update Review
Get the July 2024 security update and review.
By: Dustin Childs 2024/07/09 Read time: ( words)
Save to Folio
We’re just past the halfway point of 2024, and as expected, Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for July 2024
For July, Adobe released three patches addressing seven CVEs in Adobe Premiere Pro, InDesign, and Adobe Bridge. The patch for InDesign is the largest, fixing four Critical-rated CVEs. All four could lead to arbitrary code execution. The fix for Premiere Pro fixes a single CVE
Trendmicro
The July 2024 Security Update Review
blogs_trendmicro·2024-07-09
The July 2024 Security Update Review
# The July 2024 Security Update Review
Get the July 2024 security update and review.
By: Dustin Childs
2024/07/09
Read time: ( words)
Save to Folio
We’re just past the halfway point of 2024, and as expected, Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for July 2024
For July, Adobe released three patches addressing seven CVEs in Adobe Premiere Pro, InDesign, and Adobe Bridge. The patch for InDesign is the largest, fixing four Critical-rated CVEs. All four could lead to arbitrary code execution. The fix for Premiere Pro fixes a single CVE
ATT&CK
APT28 Nearest Neighbor Campaign
mitre_attack·CVSS 7.8
CVE-2022-38028 [HIGH] APT28 Nearest Neighbor Campaign
APT28 Nearest Neighbor Campaign
[APT28 Nearest Neighbor Campaign](https://attack.mitre.org/campaigns/C0051) was conducted by [APT28](https://attack.mitre.org/groups/G0007) from early February 2022 to November 2024 against organizations and individuals with expertise on Ukraine. APT28 primarily leveraged living-off-the-land techniques, while leveraging the zero-day exploitation of CVE-2022-38028. Notably, APT28 leveraged Wi-Fi networks in close proximity to the intended target to gain initial access to the victim environment. By daisy-chaining multiple compromised organizations nearby the intended target, APT28 discovered dual-homed systems (with both a wired and wireless network connection) to enable Wi-Fi and use compromised credentials to connect to the victim network.(Citation: Nearest
2024-07-09
Published