Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-43624

CVE-2024-43624: Windows Hyper-V Privilege Escalation Flaw

CVE-2024-43624 is a privilege escalation vulnerability in Windows Hyper-V Shared Virtual Disk that allows attackers to gain elevated privileges. This article covers the technical details, affected Windows versions, and mitigation.

Published:

CVE-2024-43624 Overview

CVE-2024-43624 is an elevation of privilege vulnerability in the Windows Hyper-V Shared Virtual Disk component. The flaw allows an authenticated attacker on the network to gain SYSTEM-level privileges on affected Hyper-V hosts. Microsoft classifies the issue under [CWE-822: Untrusted Pointer Dereference], which suggests improper handling of pointers within the shared virtual disk (VHDS) subsystem. Successful exploitation results in a full compromise of confidentiality, integrity, and availability on the targeted host.

Critical Impact

An attacker with low-privileged network access can escalate to SYSTEM on Hyper-V hosts, potentially breaking virtualization boundaries and compromising co-located virtual machines.

Affected Products

  • Microsoft Windows 10 (versions 1809, 21H2, 22H2)
  • Microsoft Windows 11 (versions 22H2, 23H2, 24H2)
  • Microsoft Windows Server 2019, 2022, 2022 23H2, and 2025

Discovery Timeline

  • 2024-11-12 - CVE-2024-43624 published to NVD as part of Microsoft's November 2024 Patch Tuesday release
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-43624

Vulnerability Analysis

The vulnerability resides in the Hyper-V Shared Virtual Disk (VHDS) implementation, which enables multiple virtual machines to access the same virtual disk simultaneously. This feature supports guest clustering scenarios such as failover clusters running inside virtual machines. An authenticated attacker with low privileges can send crafted requests over the network to trigger the flaw and execute code with elevated privileges on the Hyper-V host.

The attack scope remains unchanged, meaning exploitation impacts the vulnerable component directly. However, gaining SYSTEM on the parent partition of a Hyper-V host is particularly consequential because it can enable lateral movement into other guest virtual machines sharing that host.

Root Cause

The root cause is classified as an untrusted pointer dereference [CWE-822] within the Shared Virtual Disk handling logic. The vulnerable code path fails to validate pointer values supplied through the shared VHDS interface before dereferencing them. This allows an attacker to influence pointer contents and redirect execution flow or corrupt kernel memory structures.

Attack Vector

Exploitation requires network access to the Hyper-V host and low-privileged authentication. The attacker sends specially crafted requests targeting the Shared Virtual Disk service. No user interaction is required. Microsoft has not released technical details of the exploitation primitive, and no public proof-of-concept exploit is available at the time of publication. Refer to the Microsoft Security Update Guide CVE-2024-43624 for authoritative technical information.

Detection Methods for CVE-2024-43624

Indicators of Compromise

  • Unexpected SYSTEM-level processes spawned by vmms.exe or related Hyper-V service binaries on the parent partition
  • Anomalous access patterns against Shared Virtual Disk (.vhds) files or the associated SMB shares hosting shared virtual disks
  • Unauthorized creation of privileged accounts or scheduled tasks on Hyper-V hosts following inbound network activity

Detection Strategies

  • Monitor Windows Event Logs on Hyper-V hosts for anomalous authentication events followed by privilege escalation indicators
  • Baseline expected network traffic to Hyper-V hosts and alert on unusual RPC or SMB traffic patterns targeting the VHDS interface
  • Deploy behavioral endpoint identification on Hyper-V hosts to flag process lineage anomalies originating from virtualization services

Monitoring Recommendations

  • Enable and forward Hyper-V-Worker and Hyper-V-VMMS operational logs to a central SIEM for correlation
  • Track patch compliance across all Windows Server 2019/2022/2025 and Windows 10/11 hosts that run the Hyper-V role
  • Alert on new privileged process creation on Hyper-V hosts, especially those correlated with recent inbound network sessions

How to Mitigate CVE-2024-43624

Immediate Actions Required

  • Apply Microsoft's November 2024 security updates to all systems running the Hyper-V role, including client and server SKUs
  • Prioritize patching on production Hyper-V clusters and hosts running guest clustering with shared VHDS files
  • Audit which hosts expose the Shared Virtual Disk feature and restrict management network access to authenticated administrators only

Patch Information

Microsoft released fixes as part of the November 12, 2024 Patch Tuesday cycle. Consult the Microsoft Security Update Guide CVE-2024-43624 for the exact KB article corresponding to each affected Windows version. Verify installation using Get-HotFix or the Windows Update history after deployment.

Workarounds

  • Isolate Hyper-V management interfaces on dedicated administrative networks with strict firewall rules limiting inbound traffic
  • Enforce least privilege on Hyper-V administrator accounts and require multi-factor authentication for management access
  • Disable Shared Virtual Disk functionality on hosts where guest clustering is not required until patches are applied
bash
# Verify the November 2024 cumulative update is installed on a Hyper-V host
Get-HotFix | Sort-Object -Property InstalledOn -Descending | Select-Object -First 10

# List virtual machines using shared VHDS files to prioritize remediation
Get-VM | Get-VMHardDiskDrive | Where-Object { $_.SupportPersistentReservations -eq $true }

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.