{"api_version":"1","generated_at":"2026-06-02T09:42:40+00:00","cve":"CVE-2024-38250","urls":{"html":"https://cve.report/CVE-2024-38250","api":"https://cve.report/api/cve/CVE-2024-38250.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2024-38250","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2024-38250"},"summary":{"title":"Windows Graphics Component Elevation of Privilege Vulnerability","description":"Windows Graphics Component Elevation of Privilege Vulnerability","state":"PUBLISHED","assigner":"microsoft","published_at":"2024-09-10 17:15:30","updated_at":"2024-09-17 16:27:12"},"problem_types":["CWE-126","NVD-CWE-noinfo","CWE-126 CWE-126: Buffer Over-read"],"metrics":[{"version":"3.1","source":"secure@microsoft.com","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C","version":"3.1"}}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38250","name":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38250","refsource":"secure@microsoft.com","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-38250","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38250","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Microsoft","product":"Windows 10 Version 1809","version":"affected 10.0.17763.0 10.0.17763.6293 custom","platforms":["32-bit Systems","x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2019","version":"affected 10.0.17763.0 10.0.17763.6293 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2019 (Server Core installation)","version":"affected 10.0.17763.0 10.0.17763.6293 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2022","version":"affected 10.0.20348.0 10.0.20348.2700 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows 11 version 21H2","version":"affected 10.0.0 10.0.22000.3197 custom","platforms":["x64-based Systems","ARM64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows 10 Version 21H2","version":"affected 10.0.19043.0 10.0.19044.4894 custom","platforms":["32-bit Systems","ARM64-based Systems","x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows 11 version 22H2","version":"affected 10.0.22621.0 10.0.22621.4169 custom","platforms":["ARM64-based Systems","x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows 10 Version 22H2","version":"affected 10.0.19045.0 10.0.19045.4894 custom","platforms":["x64-based Systems","ARM64-based Systems","32-bit Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows 11 version 22H3","version":"affected 10.0.22631.0 10.0.22631.4169 custom","platforms":["ARM64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows 11 Version 23H2","version":"affected 10.0.22631.0 10.0.22631.4169 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2022, 23H2 Edition (Server Core installation)","version":"affected 10.0.25398.0 10.0.25398.1128 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows 10 Version 1507","version":"affected 10.0.10240.0 10.0.10240.20766 custom","platforms":["32-bit Systems","x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows 10 Version 1607","version":"affected 10.0.14393.0 10.0.14393.7336 custom","platforms":["32-bit Systems","x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2016","version":"affected 10.0.14393.0 10.0.14393.7336 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2016 (Server Core installation)","version":"affected 10.0.14393.0 10.0.14393.7336 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2008 Service Pack 2","version":"affected 6.0.6003.0 6.0.6003.22870 custom","platforms":["32-bit Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2008 Service Pack 2 (Server Core installation)","version":"affected 6.0.6003.0 6.0.6003.22870 custom","platforms":["32-bit Systems","x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2008  Service Pack 2","version":"affected 6.0.6003.0 6.0.6003.22870 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2008 R2 Service Pack 1","version":"affected 6.1.7601.0 6.1.7601.27320 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2008 R2 Service Pack 1 (Server Core installation)","version":"affected 6.1.7601.0 6.1.7601.27320 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2012","version":"affected 6.2.9200.0 6.2.9200.25073 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2012 (Server Core installation)","version":"affected 6.2.9200.0 6.2.9200.25073 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2012 R2","version":"affected 6.3.9600.0 6.3.9600.22175 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Windows Server 2012 R2 (Server Core installation)","version":"affected 6.3.9600.0 6.3.9600.22175 custom","platforms":["x64-based Systems"]},{"source":"CNA","vendor":"Microsoft","product":"Microsoft Office LTSC for Mac 2021","version":"affected 16.0.1 16.89.24090815 custom","platforms":["Unknown"]},{"source":"CNA","vendor":"Microsoft","product":"Microsoft Office for Android","version":"affected 16.0.1 16.0.16827.2xxxxx custom","platforms":["Unknown"]},{"source":"CNA","vendor":"Microsoft","product":"Microsoft Office for Universal","version":"affected 16.0.1 16.0.14326.21xxxx custom","platforms":["Unknown"]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"office","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"office","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"universal","cpe12":"*","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"office_long_term_servicing_channel","cpe6":"2021","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"macos","cpe12":"*","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_1507","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_1507","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x86","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_1607","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"10.0.14393.7336","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_1607","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x86","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_1809","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"arm64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_1809","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_1809","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x86","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_21h1","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"arm64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_21h1","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_21h1","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x86","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_22h2","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"arm64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_22h2","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10_22h2","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x86","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_11_21h2","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"arm64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_11_21h2","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_11_22h2","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"arm64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_11_22h2","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_11_23h2","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"arm64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_11_23h2","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2008","cpe6":"-","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2008","cpe6":"-","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x86","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2008","cpe6":"r2","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x64","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2012","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2012","cpe6":"r2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2016","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2019","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2022","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2024","cve_id":"38250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2022_23h2","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x64","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2024","cve_id":"38250","cve":"CVE-2024-38250","epss":"0.002540000","percentile":"0.488390000","score_date":"2026-05-28","updated_at":"2026-05-29 00:13:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2024-38250","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2024-09-10T18:59:14.798388Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2024-09-10T18:59:25.749Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"platforms":["32-bit Systems","x64-based Systems"],"product":"Windows 10 Version 1809","vendor":"Microsoft","versions":[{"lessThan":"10.0.17763.6293","status":"affected","version":"10.0.17763.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows Server 2019","vendor":"Microsoft","versions":[{"lessThan":"10.0.17763.6293","status":"affected","version":"10.0.17763.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows Server 2019 (Server Core installation)","vendor":"Microsoft","versions":[{"lessThan":"10.0.17763.6293","status":"affected","version":"10.0.17763.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows Server 2022","vendor":"Microsoft","versions":[{"lessThan":"10.0.20348.2700","status":"affected","version":"10.0.20348.0","versionType":"custom"}]},{"platforms":["x64-based Systems","ARM64-based Systems"],"product":"Windows 11 version 21H2","vendor":"Microsoft","versions":[{"lessThan":"10.0.22000.3197","status":"affected","version":"10.0.0","versionType":"custom"}]},{"platforms":["32-bit Systems","ARM64-based Systems","x64-based Systems"],"product":"Windows 10 Version 21H2","vendor":"Microsoft","versions":[{"lessThan":"10.0.19044.4894","status":"affected","version":"10.0.19043.0","versionType":"custom"}]},{"platforms":["ARM64-based Systems","x64-based Systems"],"product":"Windows 11 version 22H2","vendor":"Microsoft","versions":[{"lessThan":"10.0.22621.4169","status":"affected","version":"10.0.22621.0","versionType":"custom"}]},{"platforms":["x64-based Systems","ARM64-based Systems","32-bit Systems"],"product":"Windows 10 Version 22H2","vendor":"Microsoft","versions":[{"lessThan":"10.0.19045.4894","status":"affected","version":"10.0.19045.0","versionType":"custom"}]},{"platforms":["ARM64-based Systems"],"product":"Windows 11 version 22H3","vendor":"Microsoft","versions":[{"lessThan":"10.0.22631.4169","status":"affected","version":"10.0.22631.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows 11 Version 23H2","vendor":"Microsoft","versions":[{"lessThan":"10.0.22631.4169","status":"affected","version":"10.0.22631.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows Server 2022, 23H2 Edition (Server Core installation)","vendor":"Microsoft","versions":[{"lessThan":"10.0.25398.1128","status":"affected","version":"10.0.25398.0","versionType":"custom"}]},{"platforms":["32-bit Systems","x64-based Systems"],"product":"Windows 10 Version 1507","vendor":"Microsoft","versions":[{"lessThan":"10.0.10240.20766","status":"affected","version":"10.0.10240.0","versionType":"custom"}]},{"platforms":["32-bit Systems","x64-based Systems"],"product":"Windows 10 Version 1607","vendor":"Microsoft","versions":[{"lessThan":"10.0.14393.7336","status":"affected","version":"10.0.14393.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows Server 2016","vendor":"Microsoft","versions":[{"lessThan":"10.0.14393.7336","status":"affected","version":"10.0.14393.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows Server 2016 (Server Core installation)","vendor":"Microsoft","versions":[{"lessThan":"10.0.14393.7336","status":"affected","version":"10.0.14393.0","versionType":"custom"}]},{"platforms":["32-bit Systems"],"product":"Windows Server 2008 Service Pack 2","vendor":"Microsoft","versions":[{"lessThan":"6.0.6003.22870","status":"affected","version":"6.0.6003.0","versionType":"custom"}]},{"platforms":["32-bit Systems","x64-based Systems"],"product":"Windows Server 2008 Service Pack 2 (Server Core installation)","vendor":"Microsoft","versions":[{"lessThan":"6.0.6003.22870","status":"affected","version":"6.0.6003.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows Server 2008  Service Pack 2","vendor":"Microsoft","versions":[{"lessThan":"6.0.6003.22870","status":"affected","version":"6.0.6003.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows Server 2008 R2 Service Pack 1","vendor":"Microsoft","versions":[{"lessThan":"6.1.7601.27320","status":"affected","version":"6.1.7601.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows Server 2008 R2 Service Pack 1 (Server Core installation)","vendor":"Microsoft","versions":[{"lessThan":"6.1.7601.27320","status":"affected","version":"6.1.7601.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows Server 2012","vendor":"Microsoft","versions":[{"lessThan":"6.2.9200.25073","status":"affected","version":"6.2.9200.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows Server 2012 (Server Core installation)","vendor":"Microsoft","versions":[{"lessThan":"6.2.9200.25073","status":"affected","version":"6.2.9200.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows Server 2012 R2","vendor":"Microsoft","versions":[{"lessThan":"6.3.9600.22175","status":"affected","version":"6.3.9600.0","versionType":"custom"}]},{"platforms":["x64-based Systems"],"product":"Windows Server 2012 R2 (Server Core installation)","vendor":"Microsoft","versions":[{"lessThan":"6.3.9600.22175","status":"affected","version":"6.3.9600.0","versionType":"custom"}]},{"platforms":["Unknown"],"product":"Microsoft Office LTSC for Mac 2021","vendor":"Microsoft","versions":[{"lessThan":"16.89.24090815","status":"affected","version":"16.0.1","versionType":"custom"}]},{"platforms":["Unknown"],"product":"Microsoft Office for Android","vendor":"Microsoft","versions":[{"lessThan":"16.0.16827.2xxxxx","status":"affected","version":"16.0.1","versionType":"custom"}]},{"platforms":["Unknown"],"product":"Microsoft Office for Universal","vendor":"Microsoft","versions":[{"lessThan":"16.0.14326.21xxxx","status":"affected","version":"16.0.1","versionType":"custom"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.17763.6293","versionStartIncluding":"10.0.17763.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.17763.6293","versionStartIncluding":"10.0.17763.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.17763.6293","versionStartIncluding":"10.0.17763.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.20348.2700","versionStartIncluding":"10.0.20348.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_11_21H2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.22000.3197","versionStartIncluding":"10.0.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.19044.4894","versionStartIncluding":"10.0.19043.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_11_22H2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.22621.4169","versionStartIncluding":"10.0.22621.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.19045.4894","versionStartIncluding":"10.0.19045.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.22631.4169","versionStartIncluding":"10.0.22631.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.22631.4169","versionStartIncluding":"10.0.22631.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_23h2:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.25398.1128","versionStartIncluding":"10.0.25398.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.10240.20766","versionStartIncluding":"10.0.10240.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.14393.7336","versionStartIncluding":"10.0.14393.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.14393.7336","versionStartIncluding":"10.0.14393.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.14393.7336","versionStartIncluding":"10.0.14393.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x64:*","versionEndExcluding":"6.0.6003.22870","versionStartIncluding":"6.0.6003.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x64:*","versionEndExcluding":"6.0.6003.22870","versionStartIncluding":"6.0.6003.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x86:*","versionEndExcluding":"6.0.6003.22870","versionStartIncluding":"6.0.6003.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:x64:*","versionEndExcluding":"6.1.7601.27320","versionStartIncluding":"6.1.7601.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:x64:*","versionEndExcluding":"6.1.7601.27320","versionStartIncluding":"6.1.7601.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*","versionEndExcluding":"6.2.9200.25073","versionStartIncluding":"6.2.9200.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*","versionEndExcluding":"6.2.9200.25073","versionStartIncluding":"6.2.9200.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*","versionEndExcluding":"6.3.9600.22175","versionStartIncluding":"6.3.9600.0","vulnerable":true},{"criteria":"cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*","versionEndExcluding":"6.3.9600.22175","versionStartIncluding":"6.3.9600.0","vulnerable":true},{"criteria":"cpe:2.3:a:microsoft:office_long_term_servicing_channel:*:*:*:*:*:macos:*:*","versionEndExcluding":"16.89.24090815","versionStartIncluding":"16.0.1","vulnerable":true},{"criteria":"cpe:2.3:a:microsoft:office:*:*:android:*:*:*:*:*","versionEndExcluding":"16.0.16827.2xxxxx","versionStartIncluding":"16.0.1","vulnerable":true},{"criteria":"cpe:2.3:a:microsoft:office:*:*:universal:*:*:*:*:*","versionEndExcluding":"16.0.14326.21xxxx","versionStartIncluding":"16.0.1","vulnerable":true}],"negate":false,"operator":"OR"}]}],"datePublic":"2024-09-10T07:00:00.000Z","descriptions":[{"lang":"en-US","value":"Windows Graphics Component Elevation of Privilege Vulnerability"}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en-US","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-126","description":"CWE-126: Buffer Over-read","lang":"en-US","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2024-12-31T23:02:53.771Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":"Windows Graphics Component Elevation of Privilege Vulnerability","tags":["vendor-advisory"],"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38250"}],"title":"Windows Graphics Component Elevation of Privilege Vulnerability"}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2024-38250","datePublished":"2024-09-10T16:53:47.033Z","dateReserved":"2024-06-11T22:36:08.233Z","dateUpdated":"2024-12-31T23:02:53.771Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2024-09-10 17:15:30","lastModifiedDate":"2024-09-17 16:27:12","problem_types":["CWE-126","NVD-CWE-noinfo","CWE-126 CWE-126: Buffer Over-read"],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:office:-:*:*:*:*:android:*:*","matchCriteriaId":"DD6ED53F-7197-439D-A458-0DF13E16AE91"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:office:-:*:*:*:*:universal:*:*","matchCriteriaId":"20C6F097-EFA4-4A0B-BB64-D6BA2AACC706"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:*","matchCriteriaId":"BF0E8112-5B6F-4E55-8E40-38ADCF6FC654"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.10240.20766","matchCriteriaId":"85DD5735-7C22-4A98-B404-08FEF44A640F"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.10240.20766","matchCriteriaId":"83550045-529B-4968-A543-C9D298C0F31D"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.14393.7336","matchCriteriaId":"90027BBC-56AF-4F14-A118-53BBA694A0CD"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*","versionEndIncluding":"10.0.14393.7336","matchCriteriaId":"F2FBD819-1371-4941-B162-8BFCFB317EFB"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.17763.6293","matchCriteriaId":"89B89FB6-5A2C-4444-9D51-B5E46A506CA6"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.17763.6293","matchCriteriaId":"ADD534CE-0B4C-43DB-A27C-AC67246D0A87"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.17763.6293","matchCriteriaId":"23DBE62F-98CC-4F76-A841-BB20C5E8075F"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.19044.4894","matchCriteriaId":"EC7AA96F-CE3B-4E76-8BE8-A33E0E09F724"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.19044.4894","matchCriteriaId":"273D661D-7A6D-476F-9143-EBDEDD938665"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.19044.4894","matchCriteriaId":"A769F920-AB17-4C52-A416-744D91A2DE93"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.19045.4894","matchCriteriaId":"6FBDC450-FB5A-469C-8D38-9586CE5A6F48"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.19045.4894","matchCriteriaId":"6A08D353-356F-4BB0-A43F-15EBD6E2FB83"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.19045.4894","matchCriteriaId":"13DBA791-6F77-4DA1-8BF4-BA7C299C6188"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.22000.3197","matchCriteriaId":"27B86605-6710-4BC8-99A4-73462A011192"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.22000.3197","matchCriteriaId":"24ABE040-A076-4A03-9847-B4D0C2CA5E97"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.22621.4169","matchCriteriaId":"1943A041-87C3-404D-B09C-8E25E46A6E90"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.22621.4169","matchCriteriaId":"4AC8FE5E-7E85-4520-BD68-3A9776948A5D"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.22621.4169","matchCriteriaId":"76AB8812-9BA5-415B-A6B1-C5AD065D3382"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.22631.4169","matchCriteriaId":"5EFBBCCD-A83C-4D06-BBF0-1A4E5C9F0283"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*","matchCriteriaId":"2127D10C-B6F3-4C1D-B9AA-5D78513CC996"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*","matchCriteriaId":"AB425562-C0A0-452E-AABE-F70522F15E1A"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*","matchCriteriaId":"AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","matchCriteriaId":"A7DF96F8-BA6A-4780-9CA3-F719B3F81074"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","matchCriteriaId":"DB18C4CE-5917-401E-ACF7-2747084FD36E"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.14393.7336","matchCriteriaId":"A6291C92-7D32-4CC2-B601-FAF5B70F3BFD"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.17763.6293","matchCriteriaId":"BD2C9E88-C858-4B3D-A8C5-251DD6B69FD6"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.20348.2700","matchCriteriaId":"4399F533-0094-43CF-872E-FC8E4A21A904"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.25398.1128","matchCriteriaId":"E477BBBE-C862-4127-9784-B181DD05BAE5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2024","CveId":"38250","Ordinal":"1","Title":"Windows Graphics Component Elevation of Privilege Vulnerability","CVE":"CVE-2024-38250","Year":"2024"},"notes":[{"CveYear":"2024","CveId":"38250","Ordinal":"1","NoteData":"Windows Graphics Component Elevation of Privilege Vulnerability","Type":"Description","Title":"Windows Graphics Component Elevation of Privilege Vulnerability"}]}}}