Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability
Microsoft · Windows
Date added (CISA)
2024-03-04
Remediation due
2024-03-25
Known ransomware use
Yes
Remediation priority
P1 — known ransomware use · past CISA due date
Description
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.