HIGH

CVE-2023-28229

Microsoft Windows 10 1507 2023-04-11 CVSS v3.1
CVSS
7
KEV

Description

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

Summary dbcve.org

This is an elevation of privilege vulnerability in the Windows CNG (Cryptographic Next Generation) Key Isolation Service. An authenticated attacker could exploit this to gain elevated privileges on the affected Windows system, potentially executing arbitrary code with higher system rights.

Mitigation

Apply the Microsoft security updates for CVE-2023-28229 as part of the regular patch management cycle. Prioritize critical systems and domain controllers.

Patch Commit

Weakness (CWE)

CWE-591

EPSS Score

1.67%
Probability of exploitation in next 30 days
75.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE