---
title: Lazarus Hackers Exploited Windows Kernel Flaw as Zero-Day in Recent Attacks
description: "The notorious Lazarus Group actors exploited a recently patched privilege escalation flaw in the Windows Kernel as a zero-day to obtain kernel-level access and disable security software on compromised hosts. The vulnerability in question is CVE-2024-21338 (CVSS score: 7.8)."
image: https://blog.oitc.ca/hubfs/Imported_Blog_Media/windows-hacked.jpg
---

[Skip to content](https://blog.oitc.ca/alerts/lazarus-hackers-exploited-windows-kernel-flaw-as-zero-day-in-recent-attacks#main-content)

![Outsource IT Computing](https://blog.oitc.ca/hs-fs/hubfs/OITC%20Logo-1.png?width=1408&height=302&name=OITC%20Logo-1.png)Homepage

- [Services](https://oitc.ca/services)
- [Industries](https://oitc.ca/industries)
- Company
  
    - [Careers](https://oitc.ca/careers)
    - [About Us](https://oitc.ca/about)
    - [Solution Partners](https://oitc.ca/solution-partners)
    - [Community Support](https://oitc.ca/community-support)
- Resources
  
    - [Blog](https://blog.oitc.ca)
    - [Bill Payments](https://pay.oitc.ca/)
    - [VoIP 911](https://oitc.ca/v911/)
    - [Client Portal](https://portal.oitc.ca/)

[Get started](https://oitc.ca/contact/)

- [Services](https://oitc.ca/services)
- [Industries](https://oitc.ca/industries)
- Company
  
    - [Careers](https://oitc.ca/careers)
    - [About Us](https://oitc.ca/about)
    - [Solution Partners](https://oitc.ca/solution-partners)
    - [Community Support](https://oitc.ca/community-support)
- Resources
  
    - [Blog](https://blog.oitc.ca)
    - [Bill Payments](https://pay.oitc.ca/)
    - [VoIP 911](https://oitc.ca/v911/)
    - [Client Portal](https://portal.oitc.ca/)

[Get started](https://oitc.ca/contact/)

![](https://blog.oitc.ca/hs-fs/hubfs/Imported_Blog_Media/windows-hacked.jpg?width=728&height=380&name=windows-hacked.jpg)

Alerts

# Lazarus Hackers Exploited Windows Kernel Flaw as Zero-Day in Recent Attacks

![Nathan Zych](https://7528315.fs1.hubspotusercontent-na1.net/hub/7528315/hubfs/raw_assets/public/mV0_d-cms-elevate-theme_hubspot/elevate/images/avatar-placeholder.jpg?width=48&height=48&name=avatar-placeholder.jpg)

 Nathan Zych

February 29, 2024

The notorious Lazarus Group actors exploited a recently patched privilege escalation flaw in the Windows Kernel as a zero-day to obtain kernel-level access and disable security software on compromised hosts.

The vulnerability in question is [CVE-2024-21338](https://thehackernews.com/2024/02/lazarus-hackers-exploited-windows.html) (CVSS score: 7.8), which can permit an attacker to gain SYSTEM privileges. It was resolved by Microsoft earlier this month as part

[![GET UNLIMITED REMOTE AND ONSITE BUSINESS IT SUPPORT FOR A FIXED FEE](https://blog.oitc.ca/hs-fs/hubfs/Imported_Blog_Media/MSP-B-Jul-10-2025-10-12-03-6626-PM.png?width=900&name=MSP-B-Jul-10-2025-10-12-03-6626-PM.png)](https://www.oitc.ca/contact/)

[Click here to contact Outsource IT](https://www.oitc.ca/contact/)

## Share this post

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.oitc.ca%2Falerts%2Flazarus-hackers-exploited-windows-kernel-flaw-as-zero-day-in-recent-attacks><https://twitter.com/intent/tweet?url=https%3A%2F%2Fblog.oitc.ca%2Falerts%2Flazarus-hackers-exploited-windows-kernel-flaw-as-zero-day-in-recent-attacks><https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.oitc.ca%2Falerts%2Flazarus-hackers-exploited-windows-kernel-flaw-as-zero-day-in-recent-attacks><https://pinterest.com/pin/create/button/?url=https%3A%2F%2Fblog.oitc.ca%2Falerts%2Flazarus-hackers-exploited-windows-kernel-flaw-as-zero-day-in-recent-attacks>[mailto:https%3A%2F%2Fblog.oitc.ca%2Falerts%2Flazarus-hackers-exploited-windows-kernel-flaw-as-zero-day-in-recent-attacks](mailto:https%3A%2F%2Fblog.oitc.ca%2Falerts%2Flazarus-hackers-exploited-windows-kernel-flaw-as-zero-day-in-recent-attacks)

## Keep reading

### [Managed IT vs In-House IT: Why It’s Not Always an Either-Or Decision](https://blog.oitc.ca/managed-it-vs-in-house-it-why-its-not-always-an-either-or-decision)

### [Blog 10 Signs You’ve Outgrown Your Current IT Provider](https://blog.oitc.ca/10-signs-youve-outgrown-your-current-it-provider)

[![OITC Logo-1](https://blog.oitc.ca/hs-fs/hubfs/OITC%20Logo-1.png?width=300&height=64&name=OITC%20Logo-1.png "OITC Logo-1")](https://oitc.ca)

<https://www.linkedin.com/organization/1598823/><https://www.facebook.com/outsourceitcomputing/><https://x.com/oitc_ca>

---

[Privacy Policy](https://oitc.ca/privacy-policy/) · © 2025. All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Nathan Zych",
    "url" : "https://blog.oitc.ca/author/nathan-zych"
  },
  "dateModified" : "2025-07-10T22:12:24.961Z",
  "datePublished" : "2024-02-29T11:18:33.000Z",
  "headline" : "Lazarus Hackers Exploited Windows Kernel Flaw as Zero-Day in Recent Attacks",
  "mainEntityOfPage" : {
    "@id" : "https://blog.oitc.ca/alerts/lazarus-hackers-exploited-windows-kernel-flaw-as-zero-day-in-recent-attacks",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.oitc.ca/hubfs/OITC%20Logo-1.png"
    }
  }
}
```