CVE-2024-38136 is an Elevation of Privilege vulnerability in the Windows Resource Manager PSM Service Extension, affecting multiple versions of Windows 10, 11, and Server. With a CVSS score of 7.0 (HIGH), it allows a low-privileged attacker to achieve high impact on confidentiality, integrity, and availability with high attack complexity. While not currently in CISA's KEV catalog or having public exploit code like Metasploit or ExploitDB, it was addressed in Microsoft's August 2024 Patch Tuesday, which included fixes for nine zero-days. Community discussion and media coverage are minimal, suggesting limited public awareness of this specific vulnerability despite its inclusion in a significant patch release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.6189CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:* | ||
< 10.0.19044.4780CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.4780CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22000.3147CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.22621.4037CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.