CVE-2024-30030HighCVSS 7.8
Win32k Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, privileges required is Low (PR:L). What does that mean for this vulnerability? To exploit this vulnerability an attacker must have an account with the User role assigned.
🎯 Affected products6
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
✅ Remediation
KB5037800 (Monthly Rollup) — fixed build 6.0.6003.22668 KB5037836 (Security Only) — fixed build 6.0.6003.22668 KB5037780 (Monthly Rollup) — fixed build 6.1.7601.27117 KB5037803 (Security Only) — fixed build 6.1.7601.27117
🔗 References (9)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30030
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5037800
- referencehttps://support.microsoft.com/help/5037800
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5037836
- referencehttps://support.microsoft.com/help/5037836
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5037780
- referencehttps://support.microsoft.com/help/5037780
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5037803
- referencehttps://support.microsoft.com/help/5037803