#VU95851 Integer overflow in Windows and Windows Server - CVE-2024-38144
Published: August 13, 2024 / Updated: October 9, 2024
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to integer overflow in Kernel Streaming WOW Thunk Service Driver. A remote user can pass specially crafted data to the application, trigger integer overflow and gain elevated privileges on the target system.