CVE-2024-6769
A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process to a high integrity process without the intervention of a UAC prompt.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.4
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 1.08%
- CWE
- CWE-426, CWE-427
- Published
- 2024-09-26
- Last modified
- 2026-03-13
Affected products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
- Microsoft Windows Server 2022
Weakness type
Related vulnerabilities
- CVE-2025-49457 — Zoom Clients for Windows - Untrusted Search Path
- CVE-2025-49124 — Apache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for Windows
- CVE-2025-65078 — Untrusted search path vulnerability in Embedded Solutions Framework
- CVE-2024-58250 — The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.
- CVE-2025-31480 — aiven-extras allows PostgreSQL Privilege Escalation through format function
- CVE-2025-23266 — NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
- CVE-2024-44103 — DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local aut
- CVE-2026-29089 — TimescaleDB uses untrusted search path during extension upgrade