A recently addressed security vulnerability in Microsoft Windows was leveraged as a zero-day exploit by Lazarus Group, a well-known state-sponsored hacker group linked to North Korea.
This vulnerability, identified as CVE-2024-38193 with a CVSS score of 7.8, is a privilege escalation issue within the Windows Ancillary Function Driver (AFD.sys) related to WinSock.
According to a recent advisory from Microsoft, exploiting this flaw could allow an attacker to achieve SYSTEM-level privileges. The issue was resolved in Microsoft’s latest Patch Tuesday update.
The discovery and reporting of this vulnerability are attributed to Gen Digital researchers Luigino Camastra and Milánek. Gen Digital, which owns various security and utility software brands including Norton, Avast, Avira, AVG, ReputationDefender, and CCleaner, reported that they uncovered the exploit in early June 2024.
The company explained that the flaw enabled unauthorized access to critical system areas that are generally protected from standard users and administrators. The attackers used a rootkit named FudModule to avoid detection.
Although detailed technical information about these intrusions is not fully disclosed, this vulnerability bears similarities to another privilege escalation issue fixed by Microsoft in February 2024. This earlier vulnerability, CVE-2024-21338 (also with a CVSS score of 7.8), involved a Windows kernel issue in the AppLocker driver (appid.sys) and was also used by the Lazarus Group to deploy the FudModule rootkit.
Both vulnerabilities are significant because they represent an evolution beyond the traditional Bring Your Own Vulnerable Driver (BYOVD) attacks. Instead of introducing a vulnerable driver, these attacks exploit existing drivers on the Windows system to bypass security measures.
Previous reports by Avast highlighted that the FudModule rootkit was delivered via a remote access trojan called Kaolin RAT. Avast noted that FudModule is strategically deployed within the Lazarus Group’s malware framework and used selectively under specific conditions.



