Back to Labs
Security Advisory

CVE-2024-21442

About

Windows USB Print Driver Elevation of Privilege Vulnerability

Weakness (CWE):CWE-170

Rainforest analyst review

This is a local elevation-of-privilege bug in the Windows USB Print Driver. Microsoft's summary is terse, and the vector fills in the shape: a low-privileged attacker already executing on the machine abuses the print-driver component to raise their privileges, with the affected surface spanning Windows 10 and 11 and Windows Server 2022. It's not a remote entry point — it's the step that turns an existing foothold into higher, likely SYSTEM-level, control.

That places it squarely in the post-compromise toolkit. EoP flaws like this don't get an attacker onto a host; they matter once one is there — after a phishing payload, a malicious app, or a low-privilege service compromise — as the pivot to full control that unlocks credential theft, persistence, and lateral movement. Local print-driver escalations have a strong track record of being folded into real intrusion chains, so this is a when-not-if inclusion for post-access tooling.

Because it's broadly present across the Windows fleet, our angle is patch coverage on the monthly cadence rather than perimeter reachability. We track deployment of the fix across all affected editions and weight endpoints that host untrusted or lower-trust code most heavily, since that's where a local EoP pays off fastest. It won't be an initial breach, but leaving it unpatched hands any foothold a clean route to SYSTEM.

References

Related CVEs

No related CVEs.

Frequently asked questions

What is CVE-2024-21442?

Windows USB Print Driver Elevation of Privilege Vulnerability

How severe is CVE-2024-21442?

CVE-2024-21442 carries a CVSS 3.1 base score of 7.8, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 73 out of 100, in the high band.

How is CVE-2024-21442 exploited?

According to the CVSS vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H): attack vector Local, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2024-21442?

Public advisories list the following as affected: windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2022, +1. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2024-21442?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email