CVE-2024-21431HighCVSS 7.8

Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability

Published
March 12, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What kind of security feature could be bypassed by successfully exploiting this vulnerability? A hypervisor-protected code integrity (HVCI) security feature bypass vulnerability could exist when Windows incorrectly allows certain kernel-mode pages to be marked as Read, Write, Execute (RWX) even with HVCI enabled. To exploit this vulnerability an attacker could run a specially crafted script at administrator level that exploits a signed driver to bypass code integrity protections in Windows.

🎯 Affected products15

  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 23H2 for ARM64-based Systems
  • Windows 11 Version 23H2 for x64-based Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)
  • Windows Server 2022, 23H2 Edition (Server Core installation)

✅ Remediation

KB5035857 (Security Update) — fixed build 10.0.20348.2340 KB5035959 (SecurityHotpatchUpdate) — fixed build 10.0.20348.2333 KB5035854 (Security Update) — fixed build 10.0.22000.2836 KB5035845 (Security Update) — fixed build 10.0.19044.4170 KB5035853 (Security Update) — fixed build 10.0.22621.3296 KB5035845 (Security Update) — fixed build 10.0.19045.4170 KB5035853 (Security Update) — fixed build 10.0.22631.3296 KB5035856 (Security Update) — fixed build 10.0.25398.763

🔗 References (13)