CVE-2024-37985 is a Windows Kernel Information Disclosure Vulnerability affecting Microsoft Windows 11 versions 22H2 and 23H2. It carries a medium CVSS score of 5.6, indicating that an attacker with low privileges could exploit it with high attack complexity to achieve high confidentiality impact, potentially disclosing sensitive kernel information. While not currently listed in CISA's KEV catalog, its EPSS score is low, suggesting a low probability of exploitation. There is no public exploit code available, but it has garnered some community discussion and media coverage as part of Microsoft's July 2024 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.22621.3880CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.22631.3880CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.