Cyber Resilience

CVE-2024-30099

Race Condition in Microsoft Windows 10 1507 ≤ 10.0.10240.20680

Published
11 June 2024
Modified
20 July 2026
Patch / advisory
CVSS Score v3.1 7.0
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0054 42th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2024-30099 is a high-severity Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) vulnerability in Microsoft Windows 10 1507. Its CVSS base score is 7.0 (High).

Operationally, ranked at the 42th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Windows Kernel Elevation of Privilege Vulnerability

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-21362Same product: Microsoft Windows 10 1507
CVE-2024-30088Same product: Microsoft Windows 10 1507
CVE-2024-21433Same product: Microsoft Windows 10 1507
CVE-2024-43511Same product: Microsoft Windows 10 1507
CVE-2024-21371Same product: Microsoft Windows 10 1507
CVE-2024-38186Same product: Microsoft Windows 10 1607
CVE-2024-30084Same product: Microsoft Windows 10 1507
CVE-2024-38153Same product: Microsoft Windows 10 1507
CVE-2025-48818Same product: Microsoft Windows 10 1507
CVE-2024-29062Same product: Microsoft Windows 10 1507

Affected Assets

microsoft
windows 10 1507
≤ 10.0.10240.20680
microsoft
windows 10 1607
≤ 10.0.14393.7070
microsoft
windows 10 1809
≤ 10.0.17763.5936
microsoft
windows 10 21h2
≤ 10.0.19044.4529
microsoft
windows 10 22h2
≤ 10.0.19045.4529
microsoft
windows 11 21h2
≤ 10.0.22000.3019
microsoft
windows 11 22h2
≤ 10.0.22621.3737
microsoft
windows 11 23h2
≤ 10.0.22631.3737
microsoft
windows server 2016
≤ 10.0.14393.7070
microsoft
windows server 2019
≤ 10.0.17763.5936
+2 more product configuration(s) — see NVD for full list

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V15.4.2
  • V17.2.6

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-367

Timestamps meeting UTC or offset standards help identify TOCTOU issues through precise chronological reconstruction of check/use operations.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly include coding standards and reviews that prevent TOCTOU race conditions.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

none

Reliable, synchronized time across systems narrows the exploitable window in which a resource state can change between a security check and its use.

References