« Back to list

CVE-2024-38127

Status: AnalyzedHigh (7.8)—💥 PoC

Windows Hyper-V Elevation of Privilege Vulnerability

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

💥 Public exploits

Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.

⚠️ GitHub proofs of concept are not verified: some are fake or contain malware. Never run them outside an isolated lab.

Affected technologies (15)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-38127",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-38127",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-13T17:58:48.179649Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@microsoft.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 1809",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.17763.0",
              "lessThan": "10.0.17763.6189",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2019",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.17763.0",
              "lessThan": "10.0.17763.6189",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2019 (Server Core installation)",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.17763.0",
              "lessThan": "10.0.17763.6189",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2022",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.20348.0",
              "lessThan": "10.0.20348.2655",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 11 version 21H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.0",
              "lessThan": "10.0.22000.3147",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems",
            "ARM64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 21H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.19043.0",
              "lessThan": "10.0.19044.4780",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 11 version 22H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.22621.0",
              "lessThan": "10.0.22621.4037",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "ARM64-based Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 22H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.19045.0",
              "lessThan": "10.0.19045.4780",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 11 version 22H3",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.22631.0",
              "lessThan": "10.0.22631.4037",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "ARM64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 11 Version 23H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.22631.0",
              "lessThan": "10.0.22631.4037",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.25398.0",
              "lessThan": "10.0.25398.1085",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 1507",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.10240.0",
              "lessThan": "10.0.10240.20751",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 1607",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.14393.0",
              "lessThan": "10.0.14393.7259",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2016",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.14393.0",
              "lessThan": "10.0.14393.7259",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2016 (Server Core installation)",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.14393.0",
              "lessThan": "10.0.14393.7259",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2008 R2 Service Pack 1",
          "versions": [
            {
              "status": "affected",
              "version": "6.1.7601.0",
              "lessThan": "6.1.7601.27277",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
          "versions": [
            {
              "status": "affected",
              "version": "6.1.7601.0",
              "lessThan": "6.1.7601.27277",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2012",
          "versions": [
            {
              "status": "affected",
              "version": "6.2.9200.0",
              "lessThan": "6.2.9200.25031",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2012 (Server Core installation)",
          "versions": [
            {
              "status": "affected",
              "version": "6.2.9200.0",
              "lessThan": "6.2.9200.25031",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2012 R2",
          "versions": [
            {
              "status": "affected",
              "version": "6.3.9600.0",
              "lessThan": "6.3.9600.22134",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2012 R2 (Server Core installation)",
          "versions": [
            {
              "status": "affected",
              "version": "6.3.9600.0",
              "lessThan": "6.3.9600.22134",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 11 Version 24H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.26100.0",
              "lessThan": "10.0.26100.1457",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "ARM64-based Systems",
            "x64-based Systems"
          ]
        }
      ]
    }
  ],
  "published": "2024-08-13T18:15:14.597",
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38127",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secure@microsoft.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secure@microsoft.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-126"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Windows Hyper-V Elevation of Privilege Vulnerability"
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de elevación de privilegios de Windows Hyper-V"
    }
  ],
  "lastModified": "2026-06-17T07:39:29.193",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "446E539F-A4D6-43FD-A4D7-90EF7ED67892",
              "versionEndExcluding": "10.0.10240.20751"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "FA0304FD-3109-4A15-A2BC-CB1AA66C7877",
              "versionEndExcluding": "10.0.14393.7259"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "C4CD3CA7-0976-48E3-9304-66369FD13F81",
              "versionEndExcluding": "10.0.17763.6189"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "A11D3053-21AC-4260-BF3C-6382EE015932",
              "versionEndExcluding": "10.0.19044.4780"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "9637D3C1-FA14-4086-962D-7270EA576D02",
              "versionEndExcluding": "10.0.19045.4780"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66EC161E-9908-4511-933C-727D46A8271E",
              "versionEndExcluding": "10.0.22000.3147"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE5B452D-B921-4E5F-9C79-360447CD3BF8",
              "versionEndExcluding": "10.0.22621.4037"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B56F0E20-88FD-4A42-B5DE-06A6D2FAC6FA",
              "versionEndExcluding": "10.0.22631.4037"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C7E2433-4D16-40E5-973A-42F651779A47",
              "versionEndExcluding": "10.0.26100.1457"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28824912-3E9D-4E1E-AE1F-F9700DB892C0",
              "versionEndExcluding": "6.2.9200.25031"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CA31F69-6718-4968-8B0D-88728179F3CA",
              "versionEndExcluding": "10.0.14393.7259"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2267317-26DF-4EB8-A7EA-EA467727DA71",
              "versionEndExcluding": "10.0.17763.6189"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E3975C0-EA3C-4B85-94BC-43BA94474FCA",
              "versionEndExcluding": "10.0.20348.2655"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "094C36FE-9CCB-4148-AA0F-5727D6933768",
              "versionEndExcluding": "10.0.25398.1085"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}