HIGH

CVE-2023-36033

Microsoft Windows 10 1809 2023-11-14 CVSS v3.1
CVSS
7.8
KEV

Description

Windows DWM Core Library Elevation of Privilege Vulnerability

Summary dbcve.org

This is an elevation of privilege vulnerability in the Windows Desktop Window Manager (DWM) Core Library. The vulnerability allows a local authenticated attacker to escalate their privileges to SYSTEM level by exploiting a flaw in the DWM Core component.

Mitigation

Apply the Microsoft security update (KB5031445 or subsequent) to remediate this vulnerability in all affected Windows systems.

Patch Commit

Weakness (CWE)

CWE-822
CWE-119 Memory Buffer Bounds Error

EPSS Score

11.98%
Probability of exploitation in next 30 days
96th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE