CVE-2024-21302
Last modified
CVE-2024-21302 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulnerability. An elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machine SKUS. EPSS estimates a 1.56% chance of exploitation in the next 30 days.
Description
Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulnerability. An elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machine SKUS. This vulnerability enables an attacker with administrator privileges to replace current versions of Windows system files with outdated versions. By exploiting this vulnerability, an attacker could reintroduce previously mitigated vulnerabilities, circumvent some features of VBS, and exfiltrate data protected by VBS. Update: July 10, 2025 Microsoft has addressed this vulnerability for Windows 10 1507, Windows 10, version 1607, Windows 10, version 1809, and Windows Server 2016 and Windows Server 2018. This ensures that mitigations are available to protect all supported versions of Windows 10 and Windows 11 from this vulnerability. See the available mitigations and deployment guidelines described in KB5042562: Guidance for blocking rollback of virtualization-based security related updates. Update: August 13, 2024 Microsoft has released the August 2024 security updates that include an opt-in revocation policy mitigation to address this vulnerability. Customers running affected versions of Windows are encouraged to review KB5042562: Guidance for blocking rollback of virtualization-based security related updates to assess if this opt-in policy meets the needs of their environment before implementing this mitigation. There are risks associated with this mitigation that should be understood prior to applying it to your systems. Detailed information about these risks is also available in KB5042562. Details: A security researcher informed Microsoft of an elevation of privilege vulnerability in Windows 10, Windows 11, Windows Server 2016, and higher based systems including Azure Virtual Machines (VM) that support VBS. For more information on Windows versions and VM SKUs supporting VBS, reference: Virtualization-based Security (VBS) | Microsoft Learn. The vulnerability enables an attacker with administrator privileges on the target system to replace current Windows system files with outdated versions. Successful... See more at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21302
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 10 1507 | < 10.0.10240.20710 |
| Microsoft | Windows 10 1607 | < 10.0.14393.7259 |
| Microsoft | Windows 10 1809 | < 10.0.17763.6189 |
| Microsoft | Windows 10 21h2 | < 10.0.19044.4780 |
| Microsoft | Windows 10 22h2 | < 10.0.19045.4780 |
| Microsoft | Windows 11 21h2 | < 10.0.22000.3147 |
| Microsoft | Windows 11 22h2 | < 10.0.22621.4037 |
| Microsoft | Windows 11 23h2 | < 10.0.22631.4037 |
| Microsoft | Windows 11 24h2 | < 10.0.26100.1457 |
| Microsoft | Windows Server 2016 | < 10.0.14393.7259 |
| Microsoft | Windows Server 2019 | < 10.0.17763.6189 |
| Microsoft | Windows Server 2022 | < 10.0.20348.2655 |
| Microsoft | Windows Server 2022 23h2 | < 10.0.25398.1085 |
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21302Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-21302?
How severe is CVE-2024-21302?
How do I fix CVE-2024-21302?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-21284Vulnerability in the Oracle Banking Liquidity Management pro…7.1
- CVE-2024-21285Vulnerability in the Oracle Banking Liquidity Management pro…7.1
- CVE-2024-21286Vulnerability in the PeopleSoft Enterprise ELM Enterprise Le…5.4
- CVE-2024-21287Vulnerability in the Oracle Agile PLM Framework product of O…7.5
- CVE-2024-2129The WPBITS Addons For Elementor Page Builder plugin for Word…5.4
- CVE-2024-2130The CWW Companion plugin for WordPress is vulnerable to Stor…5.4
- CVE-2024-21303SQL Server Native Client OLE DB Provider Remote Code Executi…8.8
- CVE-2024-21304Trusted Compute Base Elevation of Privilege Vulnerability4.1
- CVE-2024-21305Hypervisor-Protected Code Integrity (HVCI) Security Feature …4.4
- CVE-2024-21306Microsoft Bluetooth Driver Spoofing Vulnerability5.7
- CVE-2024-21307Remote Desktop Client Remote Code Execution Vulnerability7.5
- CVE-2024-21308SQL Server Native Client OLE DB Provider Remote Code Executi…8.8
Are you affected by CVE-2024-21302?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
