Public exploitation evidence

CVE-2024-10924

As of 2026-07-28, CVE-2024-10924 has substantial public exploitation evidence: a public exploit module, a published exploit and a proof of concept. Most recent observation: 2026-06-18.

Published to NVD: 2024-11-15.

Observation timeline

Every public observation ESIP has recorded for this CVE, with its source and date. Follow any one to the original evidence.

ObservationSourceDate
Public proof-of-concept GitHub PoC 2026-06-18 View →
Public exploit reference ExploitDB 2026-04-03 View →
Public exploit module Metasploit 2026-04-03 View →

Exposure class & technique

This is one exposure signal: it describes an exposure class, not any one organization's assets. The MITRE ATT&CK techniques mapped to it:

T1014 · RootkitT1078 · Valid Accounts

Weakness (CWE)

The MITRE CWE weakness types classified for this exposure class:

CWE-288 · Authentication Bypass Using an Alternate Path or Channel CWE-306 · Missing Authentication for Critical Function
Commercial assessment

ESIP's current exposure signal for this CVE, its lifecycle state, trend, velocity, and corroboration, is available through the commercial API.

Get the assessment →

Public evidence is not the whole picture. Limited or absent observed evidence is not the same as safety.

Related CVEs

Related CVEs: those that share an ATT&CK technique or CWE weakness with this one.

Look it up yourself

Get a free key and look up any CVE yourself.

New to this? See what an exposure signal is and how ESIP builds one.

Data provided by ESIP / ZenzizenSec — www.exposuresignal.io · as of 2026-07-28