CVE-2024-38080

high

Description

Windows Hyper-V Elevation of Privilege Vulnerability

From the Tenable Blog

Microsoft’s July 2024 Patch Tuesday Addresses 138 CVEs (CVE-2024-38080, CVE-2024-38112)
Microsoft’s July 2024 Patch Tuesday Addresses 138 CVEs (CVE-2024-38080, CVE-2024-38112)

Published: 2024-07-09

Microsoft addresses 138 CVEs in its July 2024 Patch Tuesday release, with five critical vulnerabilities and three zero-day vulnerabilities, two of which were exploited in the wild.

References

https://securityonline.info/microsoft-confirms-cve-2024-37985-as-zero-day-bug-in-windows/?&web_view=true#google_vignette

https://www.tenable.com/blog/microsofts-july-2024-patch-tuesday-addresses-138-cves-cve-2024-38080-cve-2024-38112

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38080

Details

Source: Mitre, NVD

Published: 2024-07-09

Updated: 2024-07-10

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High