Microsoft released fixes for multiple Windows elevation-of-privilege vulnerabilities, including CVE-2024-30093 in Windows Storage and CVE-2024-30076 in the Windows Container Manager Service. Both issues were published through the Microsoft Security Response Center update guide as local privilege escalation flaws that could allow an attacker with existing access to gain higher privileges on affected Windows systems.
The Container Manager Service issue continues a pattern of privilege escalation bugs in the same component, following earlier Microsoft advisories for CVE-2023-36723 and CVE-2022-30132. The repeated appearance of elevation-of-privilege vulnerabilities in this service highlights the need for defenders to prioritize Windows security updates, especially on systems using containers or other workloads that rely on the affected components.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2024-30093, an elevation of privilege vulnerability affecting Windows Storage.
Microsoft published a Security Update Guide entry for CVE-2024-30076, describing an elevation of privilege vulnerability in the Windows Container Manager Service.
Microsoft published a Security Update Guide entry for CVE-2023-36723, another elevation of privilege vulnerability in the Windows Container Manager Service.
Microsoft published a Security Update Guide entry for CVE-2022-30132, an elevation of privilege vulnerability affecting the Windows Container Manager Service.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.