HIGH

CVE-2023-29336

Microsoft Windows 10 1507 2023-05-09 CVSS v3.1
CVSS
7.8
KEV

Description

Win32k Elevation of Privilege Vulnerability

Summary dbcve.org

This is a privilege escalation vulnerability in the Windows win32k.sys kernel-mode driver, which handles window management and graphics operations. Successful exploitation allows a local attacker to elevate from a low-privilege account to kernel-level (SYSTEM) privileges. The vulnerability involves a flaw in how win32k.sys handles certain user-mode requests, potentially through memory corruption or improper validation.

Mitigation

Apply the Microsoft security update for CVE-2023-29336, which patches the win32k.sys driver vulnerability. Prioritize patching systems with direct user access or those exposed as jump servers, as local exploitation is required.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

40.92%
Probability of exploitation in next 30 days
98.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE