HIGH
CVE-2023-28229
CVSS
7
KEV
Description
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Summary dbcve.org
This is an elevation of privilege vulnerability in the Windows CNG (Cryptographic Next Generation) Key Isolation Service. An authenticated attacker could exploit this to gain elevated privileges on the affected Windows system, potentially executing arbitrary code with higher system rights.
Mitigation
Apply the Microsoft security updates for CVE-2023-28229 as part of the regular patch management cycle. Prioritize critical systems and domain controllers.
Weakness (CWE)
CWE-591
EPSS Score
1.67%
Probability of exploitation in next 30 days
75.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.