Exploitation observations

CVE-2024-38476

As of 2026-07-28, CVE-2024-38476 has 1 public exploitation observation, the most recent on 2026-06-20.

Published to NVD: 2024-07-01.

Observation timeline

Every public observation ESIP has recorded for this CVE, with its source and date. Follow any one to the original evidence.

ObservationSourceDate
Public proof-of-concept GitHub PoC 2026-06-20 View →

Exposure class & technique

This is one exposure signal: it describes an exposure class, not any one organization's assets. The MITRE ATT&CK techniques mapped to it:

T1055 · Process InjectionT1574 · Hijack Execution Flow

Weakness (CWE)

The MITRE CWE weakness type classified for this exposure class:

CWE-829 · Inclusion of Functionality from Untrusted Control Sphere

These are the public observations ESIP has recorded for CVE-2024-38476, dated and attributed to their sources. Whether they add up to an active exposure signal is ESIP's assessment, available through the commercial API. Public evidence is not the whole picture: limited evidence is not the same as safety. See what an exposure signal is.

Commercial assessment

ESIP's current exposure signal for this CVE, its lifecycle state, trend, velocity, and corroboration, is available through the commercial API.

Get the assessment →

Related CVEs

Related CVEs: those that share an ATT&CK technique or CWE weakness with this one.

Look it up yourself

Get a free key and look up any CVE yourself.

New to this? See what an exposure signal is and how ESIP builds one.

Data provided by ESIP / ZenzizenSec — www.exposuresignal.io · as of 2026-07-28