CVE-2024-38062
published 2024-07-09CVE-2024-38062: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.61%
73.3th percentile
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1607 | < 10.0.14393.7159 | 10.0.14393.7159 |
| microsoft | windows_10_1809 | < 10.0.17763.6054 | 10.0.17763.6054 |
| microsoft | windows_10_21h2 | < 10.0.19044.4651 | 10.0.19044.4651 |
| microsoft | windows_10_22h2 | < 10.0.19045.4651 | 10.0.19045.4651 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.7159 | 10.0.14393.7159 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.6054 | 10.0.17763.6054 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.4651 | 10.0.19044.4651 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4651 | 10.0.19045.4651 |
| microsoft | windows_11_21h2 | < 10.0.22000.3079 | 10.0.22000.3079 |
| microsoft | windows_11_22h2 | < 10.0.22621.3880 | 10.0.22621.3880 |
| microsoft | windows_11_23h2 | < 10.0.22631.3880 | 10.0.22631.3880 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.3079 | 10.0.22000.3079 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3880 | 10.0.22621.3880 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3880 | 10.0.22631.3880 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3880 | 10.0.22631.3880 |
| microsoft | windows_server_2016 | < 10.0.14393.7159 | 10.0.14393.7159 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.7159 | 10.0.14393.7159 |
| microsoft | windows_server_2019 | < 10.0.17763.6054 | 10.0.17763.6054 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.6054 | 10.0.17763.6054 |
| microsoft | windows_server_2022 | < 10.0.20348.2582 | 10.0.20348.2582 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.2582 | 10.0.20348.2582 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.1009 | 10.0.25398.1009 |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_21h2 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qjcr-wf5h-8f7g: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
ghsa_unreviewed·2024-07-09
CVE-2024-38062 [HIGH] CWE-125 GHSA-qjcr-wf5h-8f7g: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Microsoft
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
vendor_msrc·2024-07-09·CVSS 7.8
CVE-2024-38062 [HIGH] CWE-125 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Kernel-Mode Drivers: Windows Kernel-Mode Drivers
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5040430
Reference: https://support.microsoft.com/help/5040430
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5040437
Reference: https://support.microsoft.com/help/5040437
Reference: https://catalog.upda
No detection rules found.
No public exploits indexed.
Talos
Finding vulnerabilities in ClipSp, the driver at the core of Windows’ Client License Platform
blogs_talos·2024-11-25·CVSS 7.8
CVE-2024-38184 [HIGH] Finding vulnerabilities in ClipSp, the driver at the core of Windows’ Client License Platform
## Finding vulnerabilities in ClipSp, the driver at the core of Windows’ Client License Platform
By Philippe Laulheret
ClipSP (clipsp.sys) is a Windows driver used to implement client licensing and system policies on Windows 10 and 11 systems.
Cisco Talos researchers have discovered eight vulnerabilities related to clipsp.sys ranging from signature bypass to elevation of privileges and sandbox escape:
TALOS-2024-1964 (CVE-2024-38184)
TALOS-2024-1965 (CVE-2024-38185)
TALOS-2024-1966 (CVE-2024-38186)
TALOS-2024-1968 (CVE-2024-38062)
TALOS-2024-1969 (CVE-2024-38187)
TALOS-2024-1970 (CVE-2024-38062)
TALOS-2024-1971 (CVE-2024-38062)
TALOS-2024-1988 (CVE-2024-38062)
This research project was also presented at both HITCON and Hexacon. A recording of the latter’s presentation is embedd
Talos
Finding vulnerabilities in ClipSp, the driver at the core of Windows’ Client License Platform
blogs_talos·2024-11-25·CVSS 7.8
CVE-2024-38184 [HIGH] Finding vulnerabilities in ClipSp, the driver at the core of Windows’ Client License Platform
By Philippe Laulheret
ClipSP (clipsp.sys) is a Windows driver used to implement client licensing and system policies on Windows 10 and 11 systems.
Cisco Talos researchers have discovered eight vulnerabilities related to clipsp.sys ranging from signature bypass to elevation of privileges and sandbox escape:
- TALOS-2024-1964 (CVE-2024-38184)
- TALOS-2024-1965 (CVE-2024-38185)
- TALOS-2024-1966 (CVE-2024-38186)
- TALOS-2024-1968 (CVE-2024-38062)
- TALOS-2024-1969 (CVE-2024-38187)
- TALOS-2024-1970 (CVE-2024-38062)
- TALOS-2024-1971 (CVE-2024-38062)
- TALOS-2024-1988 (CVE-2024-38062)
This research project was also presented at both HITCON and Hexacon. A recording of the latter’s presentation is embedded at the end of this article.
## What is ClipSp?
ClipSp is a first-party driver on Mic
Talos
AI, election security headline discussions at Black Hat and DEF CON
blogs_talos·2024-08-15
AI, election security headline discussions at Black Hat and DEF CON
As promised, I’m back this week to recap some of the top stories coming out of Black Hat and DEF CON.
Also as promised, AI was the talk of Vegas during Hacker Summer Camp (or at least from what I’ve been reading and hearing, I wasn’t there in person).
Several exhibitions and talks at both conferences showed how easy it is to create deepfake videos and potentially use them to spread fake news and disinformation. Two security researchers worked to deepfake themselves and even managed to trick people into believing it really was them on one end of a video conference call.
Others on the show floor had the opportunity to try their hand at creating deepfakes with the help of the Defense Advanced Research Projects Agency (DARPA). One standout example was a fake video of former Royal Family mem
Talos
AI, election security headline discussions at Black Hat and DEF CON
blogs_talos·2024-08-15
AI, election security headline discussions at Black Hat and DEF CON
## AI, election security headline discussions at Black Hat and DEF CON
As promised, I’m back this week to recap some of the top stories coming out of Black Hat and DEF CON.
Also as promised, AI was the talk of Vegas during Hacker Summer Camp (or at least from what I’ve been reading and hearing, I wasn’t there in person).
Several exhibitions and talks at both conferences showed how easy it is to create deepfake videos and potentially use them to spread fake news and disinformation. Two security researchers worked to deepfake themselves and even managed to trick people into believing it really was them on one end of a video conference call.
Others on the show floor had the opportunity to try their hand at creating deepfakes with the help of the Defense Advanced Research Projects Agency (
Talos
Talos discovers 11 vulnerabilities between Microsoft, Adobe software disclosed on Patch Tuesday
blogs_talos·2024-08-14·CVSS 7.8
[HIGH] Talos discovers 11 vulnerabilities between Microsoft, Adobe software disclosed on Patch Tuesday
## Talos discovers 11 vulnerabilities between Microsoft, Adobe software disclosed on Patch Tuesday
Cisco Talos’ Vulnerability Research team recently discovered 11 vulnerabilities in Microsoft Windows CLIPSP.SYS and Adobe Acrobat Reader that were all disclosed this week as part of the company’s regular security updates.
For more on Patch Tuesday, check out Talos’ blog post here .
Eight of the vulnerabilities affect the license update feature for CLIPSP.SYS, a driver used to implement Client License System Policy on Windows 10 and 11. The three others are use-after-free or out-of-bounds read vulnerabilities in Adobe Acrobat Reader, one of the most popular PDF readers on the market currently.
Microsoft and Adobe have patched the issues mentioned in this blog post, all in adherence to Cisc
Talos
Talos discovers 11 vulnerabilities between Microsoft, Adobe software disclosed on Patch Tuesday
blogs_talos·2024-08-14·CVSS 7.8
[HIGH] Talos discovers 11 vulnerabilities between Microsoft, Adobe software disclosed on Patch Tuesday
Cisco Talos’ Vulnerability Research team recently discovered 11 vulnerabilities in Microsoft Windows CLIPSP.SYS and Adobe Acrobat Reader that were all disclosed this week as part of the company’s regular security updates.
For more on Patch Tuesday, check out Talos’ blog post here.
Eight of the vulnerabilities affect the license update feature for CLIPSP.SYS, a driver used to implement Client License System Policy on Windows 10 and 11. The three others are use-after-free or out-of-bounds read vulnerabilities in Adobe Acrobat Reader, one of the most popular PDF readers on the market currently.
Microsoft and Adobe have patched the issues mentioned in this blog post, all in adherence to Cisco’s third-party vulnerability disclosure policy, while LevelOne has declined to release a fix.
For S
Talos
Largest Patch Tuesday in 3 months includes 5 critical vulnerabilities
blogs_talos·2024-07-09·CVSS 7.2
[HIGH] Largest Patch Tuesday in 3 months includes 5 critical vulnerabilities
## Largest Patch Tuesday in 3 months includes 5 critical vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 142 vulnerabilities across its suite of products and software. Of those, there are five critical vulnerabilities, and every other security issue disclosed this month is considered "important."
This is the largest Patch Tuesday since April when Microsoft patched 150 vulnerabilities.
Of the critical vulnerabilities, two are considered more likely to be exploited:
CVE-2024-38023 , a remote code execution vulnerability in Microsoft SharePoint server, where an authenticated attacker with Site Owner permissions can use the vulnerability to execute arbitrary code in the context of SharePoint server.
CVE-2024-38060 , a remote code execution vulnerabili
Trendmicro
The July 2024 Security Update Review
blogs_trendmicro·2024-07-09
The July 2024 Security Update Review
## The July 2024 Security Update Review
Get the July 2024 security update and review.
By: Dustin Childs 2024/07/09 Read time: ( words)
Save to Folio
We’re just past the halfway point of 2024, and as expected, Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for July 2024
For July, Adobe released three patches addressing seven CVEs in Adobe Premiere Pro, InDesign, and Adobe Bridge. The patch for InDesign is the largest, fixing four Critical-rated CVEs. All four could lead to arbitrary code execution. The fix for Premiere Pro fixes a single CVE
Talos
Largest Patch Tuesday in 3 months includes 5 critical vulnerabilities
blogs_talos·2024-07-09·CVSS 7.2
CVE-2024-38023 [HIGH] Largest Patch Tuesday in 3 months includes 5 critical vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 142 vulnerabilities across its suite of products and software. Of those, there are five critical vulnerabilities, and every other security issue disclosed this month is considered "important."
This is the largest Patch Tuesday since April when Microsoft patched 150 vulnerabilities.
Of the critical vulnerabilities, two are considered more likely to be exploited:
CVE-2024-38023, a remote code execution vulnerability in Microsoft SharePoint server, where an authenticated attacker with Site Owner permissions can use the vulnerability to execute arbitrary code in the context of SharePoint server.
CVE-2024-38060, a remote code execution vulnerability in Microsoft Windows Codecs Library that can be exploited by an authentic
Trendmicro
The July 2024 Security Update Review
blogs_trendmicro·2024-07-09
The July 2024 Security Update Review
# The July 2024 Security Update Review
Get the July 2024 security update and review.
By: Dustin Childs
2024/07/09
Read time: ( words)
Save to Folio
We’re just past the halfway point of 2024, and as expected, Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for July 2024
For July, Adobe released three patches addressing seven CVEs in Adobe Premiere Pro, InDesign, and Adobe Bridge. The patch for InDesign is the largest, fixing four Critical-rated CVEs. All four could lead to arbitrary code execution. The fix for Premiere Pro fixes a single CVE
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38062https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38062https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1968https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1970https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1971https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1988
2024-07-09
Published