Microsoft disclosed multiple Elevation of Privilege vulnerabilities in the Kernel Streaming Service Driver, identifying CVE-2024-38238, CVE-2024-38244, CVE-2024-38245, and CVE-2025-24066 in its Security Update Guide. The issues affect a low-level Windows driver component and could allow an attacker to gain higher privileges on a targeted system if successfully exploited.
The advisories provide limited public technical detail, but the grouping of several CVEs against the same driver indicates repeated security weaknesses in the Windows Kernel Streaming attack surface. Organizations should prioritize Microsoft security updates covering these CVEs, review endpoint exposure across supported Windows assets, and monitor for signs of local privilege-escalation activity involving kernel-level components.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft added a Security Update Guide entry for CVE-2025-24066, another Kernel Streaming Service Driver elevation of privilege vulnerability. This marks a later, distinct disclosure and patch cycle affecting the same component family.
Microsoft published a Security Update Guide entry for CVE-2025-21375, identified as a Kernel Streaming WOW Thunk Service Driver elevation of privilege vulnerability. This represents a separate disclosure and patch event affecting the broader Kernel Streaming driver family.
Microsoft published Security Update Guide entries for CVE-2024-38238, CVE-2024-38244, and CVE-2024-38245, all described as Kernel Streaming Service Driver elevation of privilege vulnerabilities. The simultaneous publication indicates these flaws were disclosed and addressed as part of Microsoft's September 2024 security updates.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.