Introducing Wiz for Exposure Management: Unify, prioritize, and remediate exposures everywhere.

CVE-2024-26238
vulnerability analysis and mitigation

Overview

Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability (CVE-2024-26238) is a high-severity security flaw discovered in Microsoft's Windows Update component RUXIM (Reusable UX Integration Manager). The vulnerability was disclosed on May 14, 2024, affecting Windows 10 versions 2004 through 20H2, with a CVSS score of 7.8 (High) (NVD).

Technical details

The vulnerability exists in how PLUGScheduler, running with SYSTEM privileges, manages file operations within a directory accessible to standard users. The process involves creating the C:\ProgramData\PLUG\Logs folder, handling log file deletions, and renaming operations. The key vulnerability stems from permissive Access Control Lists (ACLs) of the Logs folder, which allows standard users to perform certain operations including file creation and attribute modifications (Security Online).

Impact

Successful exploitation of this vulnerability can result in attackers gaining full control of a Windows system with the highest system privileges. This allows malicious actors to execute code, install unauthorized software, and manipulate sensitive data with SYSTEM-level access (Security Online).

Mitigation and workarounds

Users are strongly advised to install security update KB 5001716, which is available through Windows Update. For additional protection, it is recommended to configure stricter access control lists (ACLs) for the C:\ProgramData\PLUG directory and its subdirectories to restrict write access to privileged users only (Security Online).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management