CVE-2024-38080
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
4 articles
EPSS Score
Source: FIRST.org · 2026-05-24
14.2%
probability
This CVE has a 14.2% probability
of being exploited in the next 30 days.
0%
Top 94.5th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroHyper-V Elevation of Privilege Vulnerability
Google Project Zero
Patched
July 9, 2024
Reported by
???
Root Cause Analysis
???
Microsoft and Adobe Patch Tuesday, July 2024 Security Update Review
Qualys
Jul 09, 2024
Microsoft July 2024 Patch Tuesday fixes 142 flaws, 4 zero-days
BleepingComputer
Jul 09, 2024
Security Advisory 2024-067
CERT-EU
Jul 12, 2024
Signal Intelligence
Confidence
92%
EPSS
14.2%
Mentions
4
Last Seen
Jul 12, 2024
CNA Information
Analyst Note
CVE-2024-38080 is confirmed as a legitimate Windows Hyper-V elevation of privilege vulnerability patched by Microsoft in July 2024. The vulnerability's inclusion in Google Project Zero and coverage by reputable security sources (BleepingComputer, CERT-EU) combined with its HIGH CVSS v3 score of 7.8 provide strong corroboration of its authenticity and impact.
Threat Actors 1
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Triage Info
Decided atMar 03, 2026