CVE-2024-38193 — Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5041782 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 for x64-based Systems | 5041782 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5041773 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5041773 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5041578 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5041578 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5041580 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5041580 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5041580 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5041580 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5041580 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5041580 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 21H2 for ARM64-based Systems | 5041592 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 21H2 for x64-based Systems | 5041592 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5041585 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5041585 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5041585 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5041585 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems | 5041571 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for x64-based Systems | 5041571 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 5041850 (Monthly Rollup) 5041847 (Security Only) Important Elevation of Privilege 5040499 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.22825 Yes 5041850 5041847 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5041850 (Monthly Rollup) 5041847 (Security Only) Important Elevation of Privilege 5040499 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.22825 Yes 5041850 5041847 Windows Server 2008 for x64-based Systems Service Pack 2 5041850 (Monthly Rollup) 5041847 (Security Only) Important Elevation of Privilege 5040499 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.22825 Yes 5041850 5041847 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5041850 (Monthly Rollup) 5041847 (Security Only) Important Elevation of Privilege 5040499 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.22825 Yes 5041850 5041847 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5041838 (Monthly Rollup) 5041823 (Security Only) Important Elevation of Privilege 5040497 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.27277 Yes 5041838 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5041838 (Monthly Rollup) 5041823 (Security Only) Important Elevation of Privilege 5040497 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.27277 Yes 5041838 Windows Server 2012 | 5041851 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 (Server Core installation) | 5041851 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 | 5041828 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5041828 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 | 5041773 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5041773 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5041578 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5041578 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 | 5041160 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 (Server Core installation) | 5041160 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022, 23H2 Edition (Server Core installation) | 5041573 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5041782 |
Security Update | Yes |
5041773 |
Security Update | Yes |
5041578 |
Security Update | Yes |
5041580 |
Security Update | Yes |
5041592 |
Security Update | Yes |
5041585 |
Security Update | Yes |
5041571 |
Security Update | Yes |
5041851 |
Monthly Rollup | Yes |
5041828 |
Monthly Rollup | Yes |
5041160 |
Security Update | Yes |
5041573 |
Security Update | Yes |
Patch Diff
Use-after-free in the Registered I/O (RIO) buffer cache (CVE-2024-38193, exploited ITW by Lazarus Group). Race condition between AfdRioGetAndCacheBuffer (_InterlockedIncrement on RIOBuffer.RefCount during cache fill) and AfdRioDereferenceBuffer (non-atomic RefCount==1 check + ExFreePool). Patch: AfdRioDereferenceBuffer uses atomic decrement with underflow bugcheck, AfdRioGetAndCacheBuffer calls new AfdRioReferenceBuffer for safe acquire, RIOBuffer.RefCount widened to 64-bit. All gated by CFR Feature_3168083257 + Feature_3695514937.
| Function | Address | Change | Note |
|---|---|---|---|
AfdRioDereferenceBuffer |
|
code (ratio 0.48, significant rewrite) | Non-atomic RefCount==1 check replaced with atomic decrement + underflow guard (swi(0x29) bugcheck). RefCount widened to 64-bit. Gated by Feature_3168083257 / Feature_3695514937 (Feature_AfdRioCachedBuffer_IsEnabled). |
AfdRioGetAndCacheBuffer |
|
code (ratio 0.48, significant rewrite) | Raw _InterlockedIncrement(&RefCount) replaced with call to new AfdRioReferenceBuffer — returns NULL if buffer already freed, eliminating the TOCTOU window. |
AfdRioReferenceBuffer (added) |
|
added function | New atomic reference-acquire: checks IsInvalid and atomically increments RefCount only if buffer is still alive, returns 0 on failure. |
AfdRioGetCachedBuffer |
|
code | Cache hit/miss dispatcher, calls AfdRioGetAndCacheBuffer on miss. |
AfdRioEvictCachedBuffer |
|
code (ratio 0.70) | Cache eviction path updated to match new RIOBuffer layout. |
AfdRioCreateRegisteredBuffer |
|
code (ratio 0.95) | RIOBuffer allocation updated for wider structure (IsInvalid +0x18→+0x24, RefCount 32→64-bit at +0x18). |
AfdRioInvalidateBuffer |
|
code (ratio 0.96) | IsInvalid field access updated for new offset. |
Attack Path
Use-after-free in the AFD Registered I/O buffer cache - a non-atomic refcount check races the cache-fill increment. Exploited in the wild by Lazarus Group.
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Known Exploits
Acknowledgments
Luigino Camastra and Milánek with Gen Digital