CVE detail
CVE-2024-38193
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
12 source links · newest first
February 2025 Patch Tuesday is here, and Microsoft has delivered fixes for 56 vulnerabilities, including two zero-days – CVE-2025-21418 and CVE-2025-21391 – under active exploitation. CVE-2025-21418 and CVE-2025-21391 CVE-2025-21418 is a vulnerability in the Windows Ancillary Function Driver (AFD.sys), which interfaces with the Windows Sockets API to enable Windows applications to connect to the internet. It can be exploited by attackers to elevate privileges on the target host. “An authenticated user would need to run … More →
newswww.helpnetsecurity.comFeb 11, 2025, 8:15 PM- Week in review: PostgreSQL databases under attack, new Chrome zero-day actively exploitedHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: PostgreSQL databases under attack Poorly protected PostgreSQL databases running on Linux machines are being compromised by cryptojacking attackers. Vulnerabilities in Microsoft macOS apps may give attackers access to microphone, camera Vulnerabilities in popular Microsoft apps for macOS can be abused by attackers to record video and audio clips, take pictures, access and exfiltrate data and send emails, Cisco Talos researchers … More →
newswww.helpnetsecurity.comAug 25, 2024, 8:00 AM - 0-day in Windows driver exploited by North Korean hackers to deliver rootkit (CVE-2024-38193)Help Net Security
CVE-2024-38193, an actively exploited zero-day that Microsoft patched earlier this month, has been leveraged by North Korean hackers to install a rootkit on targets’ computers, Gen Digital researchers have revealed. About CVE-2024-38193 CVE-2024-38193 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys). Gen Digital researchers Luigino Camastra and Milanek discovered in early June 2024 that the Lazarus APT group was exploiting the flaw to achieve SYSTEM privilege, so they can “bypass … More →
newswww.helpnetsecurity.comAug 20, 2024, 12:59 PM The vulnerability, tracked as CVE-2024-38193 and marked as ‘actively exploited’ by Microsoft, allows SYSTEM privileges on the latest Windows operating systems.
newswww.securityweek.comAug 19, 2024, 3:35 PM- 19th August – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 19th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The campaign of United States presidential nominee Donald Trump has had its internal communications hacked and leaked, allegedly by an Iranian threat actor. This aligns with Microsoft’s previous identification of a related […]
vendorresearch.checkpoint.comAug 19, 2024, 9:35 AM Microsoft addressed a zero-day vulnerability actively exploited by the North-Korea-linked Lazarus APT group. Microsoft has addressed a zero-day vulnerability, tracked as CVE-2024-38193 (CVSS score: 7.8), which has been exploited by the North Korea-linked Lazarus APT group. The vulnerability, tracked as CVE-2024-38193 (CVSS score: 7.8), is a privilege escalation issue that resides in the Windows Ancillary Function Driver (AFD.sys) for […]
newssecurityaffairs.comAug 19, 2024, 8:41 AMMicrosoft addressed a critical zero-click Windows remote code execution (RCE) in the TCP/IP stack that impacts all systems with IPv6 enabled. Microsoft urges customers to fix a critical TCP/IP remote code execution (RCE) flaw, tracked as CVE-2024-38063 (CVSS score 9.8), in the TCP/IP stack. The vulnerability impacts all systems with IPv6 enabled (IPv6 is enabled by […]
newssecurityaffairs.comAug 16, 2024, 7:10 AMSecurity experts are ratcheting up the urgency for Windows admins to patch a wormable, pre-auth remote code execution vulnerability in the Windows TCP/IP stack.
newswww.securityweek.comAug 15, 2024, 3:39 PM- Microsoft Patch Tuesday security updates for August 2024 addressed six actively exploited bugsSecurity Affairs
Microsoft’s August 2024 Patch Tuesday addressed 90 vulnerabilities, including six that are actively exploited. Patch Tuesday security updates for August 2024 addressed 90 vulnerabilities in Microsoft products including Windows and Windows Components; Office and Office Components; .NET and Visual Studio; Azure; Co-Pilot; Microsoft Dynamics; Teams; and Secure Boot and others, bringing the total to 102 […]
newssecurityaffairs.comAug 14, 2024, 7:13 AM Microsoft fixed 88 vulnerabilities on Tuesday as part of its monthly patching cycle. Six of those flaws were already being actively exploited in the wild before a patch was available and another four were publicly disclosed, putting the total number of zero-day vulnerabilities covered in this release at 10. Of the 88 vulnerabilities patched only […]
newswww.csoonline.comAug 13, 2024, 10:59 PM- Microsoft fixes 6 zero-days under active attackHelp Net Security
August 2024 Patch Tuesday is here, and Microsoft has delivered fixes for 90 vulnerabilities, six of which have been exploited in the wild as zero-days, and four are publicly known. The zero-days under attack CVE-2024-38178 is a Scripting Engine Memory Corruption Vulnerability that could lead to remote code execution. Reported by AhnLab and South Korea’s National Cyber Security Center (NCSC), the flaw can be successfully exploited only if the target uses Microsoft Edge in Internet … More →
newswww.helpnetsecurity.comAug 13, 2024, 8:09 PM Microsoft’s security response team pushed out documentation for almost 90 vulnerabilities across Windows and OS components and marked several flaws in the actively exploited category.
newswww.securityweek.comAug 13, 2024, 7:02 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-43599CVSS 8.8 · High
Remote Desktop Client Remote Code Execution Vulnerability
- CVE-2024-43570CVSS 6.4 · Medium
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2024-43556CVSS 7.8 · High
Windows Graphics Component Elevation of Privilege Vulnerability
- CVE-2024-43535CVSS 7.0 · High
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
- CVE-2024-43509CVSS 7.8 · High
Windows Graphics Component Elevation of Privilege Vulnerability
- CVE-2024-38249CVSS 7.8 · High
Windows Graphics Component Elevation of Privilege Vulnerability