Vulnerability record · CVE-2024-30088 · published 11 June 2024
CVE-2024-30088: Windows Kernel TOCTOU race condition privilege escalation
Microsoft · Windows 10 1507
CVE-2024-30088 is a time-of-check time-of-use (TOCTOU) race condition in the Windows kernel that allows a local user to elevate privileges. It affects a broad set of Windows 10, Windows 11 and Windows Server releases, and Microsoft has issued a patch. Because it is a kernel elevation flaw, successful exploitation gives an attacker full control of the host, which is why it is a high-value target for post-compromise activity.
Description
Windows Kernel Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a patched kernel elevation flaw with confirmed exploitation in the wild and known ransomware use, but it requires local access and a race condition to succeed.
What it is
CVE-2024-30088 is a time-of-check time-of-use (TOCTOU) race condition in the Windows kernel that allows a local user to elevate privileges. It affects a broad set of Windows 10, Windows 11 and Windows Server releases, and Microsoft has issued a patch. Because it is a kernel elevation flaw, successful exploitation gives an attacker full control of the host, which is why it is a high-value target for post-compromise activity.
Impact
An attacker who wins the race gains elevated privileges in the kernel, effectively SYSTEM-level control of the affected machine. From there they can disable security tooling, move laterally, or deploy ransomware.
Attack surface
The vulnerability is local (AV:L) and requires low privileges (PR:L) with no user interaction (UI:N), so an attacker must already have code execution or an interactive session on the target host. It is not remotely reachable and does not require a victim to open a file or click a link.
Exploitation
CVE-2024-30088 is listed in CISA's Known Exploited Vulnerabilities catalog with a due date of 2024-11-05 and is flagged for known ransomware campaign use. EPSS gives it a 30-day exploitation probability of roughly 0.68 (99.3rd percentile), indicating active, widespread exploitation.
What to do
- Apply the Microsoft security update for CVE-2024-30088 to all affected Windows 10, Windows 11 and Windows Server builds as the first action.
- Prioritize patching internet-facing and high-value hosts, and treat any unpatched system as compromised until proven otherwise.
- Restrict local interactive logon and administrative rights to reduce the pool of accounts that can trigger the race condition.
- Enable and tune kernel-level exploit protection and endpoint detection to catch privilege-escalation behavior.
- Track CISA KEV remediation deadlines and confirm patching through vulnerability scanning.
Detection
- Monitor for unexpected processes gaining SYSTEM or kernel-level privileges, especially short-lived or unusual parent-child process relationships.
- Alert on suspicious token manipulation or privilege escalation attempts in Windows security event logs (e.g., 4672, 4688) from non-administrative accounts.
- Hunt for known exploit tooling or post-exploitation behavior associated with kernel EoP, such as driver loading or security service tampering.
- Correlate local privilege escalation events with subsequent lateral movement or ransomware precursor activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-30088 to the Known Exploited Vulnerabilities catalog on 15 October 2024 as "Microsoft Windows Kernel TOCTOU Race Condition Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 5 November 2024.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30088 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30088 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-30088 | US Government Resource |
Track CVE-2024-30088 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-30088), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.