CVE-2024-38107

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 3 articles

EPSS Score

Source: FIRST.org · 2026-05-24
3.35%
probability
This CVE has a 3.35% probability of being exploited in the next 30 days.
0% Top 87.5th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Windows Power Dependency Coordinator Elevation of Privilege (use after free)

Attack Intelligence

Google Project Zero

Patched
Aug. 13, 2024
Reported by
Anonymous
Root Cause Analysis
???

Signal Intelligence

Confidence
78%
EPSS 3.35%
Mentions 3
Last Seen Aug 13, 2024

CNA Information

Analyst Note

CVE-2024-38107 is confirmed as a zero-day vulnerability affecting Windows 10 with a HIGH CVSS score of 7.8, reported by Google Project Zero and documented in Microsoft's August 2024 Patch Tuesday bulletin addressing 9 zero-days. The elevation of privilege nature and inclusion in a major vendor security update provides strong validation of the threat.

Triage Info

Decided atMar 03, 2026