Netskope Threat Labs

OS-WINDOWS Microsoft Windows Kernel Streaming WOW Thunk Service driver escalation of privilege attempt

IPS-SWG

2 SIDs: 63699, 63988

Detects an attempt to exploit CVE-2024-38052, CVE-2024-38054, and CVE-2024-38237, a privilege escalation flaw that can grant higher access in Microsoft Windows Kernel Streaming WOW Thunk Service driver.