HIGH
CVE-2023-29336
CVSS
7.8
KEV
Description
Win32k Elevation of Privilege Vulnerability
Summary dbcve.org
This is a privilege escalation vulnerability in the Windows win32k.sys kernel-mode driver, which handles window management and graphics operations. Successful exploitation allows a local attacker to elevate from a low-privilege account to kernel-level (SYSTEM) privileges. The vulnerability involves a flaw in how win32k.sys handles certain user-mode requests, potentially through memory corruption or improper validation.
Mitigation
Apply the Microsoft security update for CVE-2023-29336, which patches the win32k.sys driver vulnerability. Prioritize patching systems with direct user access or those exposed as jump servers, as local exploitation is required.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
40.92%
Probability of exploitation in next 30 days
98.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.