Junglewise Threat Intelligence

CVE-2023-21823: Microsoft Windows Graphic Component Privilege Escalation Vulnerability

CVE-2023-21823 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-02-14

Technologies: Microsoft Windows, Microsoft Windows 11, Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019. Vendors: Microsoft.

Executive brief

An integer overflow vulnerability in the Microsoft Windows Graphics Component allows a local attacker to escalate privileges to SYSTEM. The vulnerability has been confirmed to be exploited in the wild.

Affected products

  • Microsoft Windows 10 1507, 1607, 1809, 20H2, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2022

Timeline

  • 2023-02-14: disclosed
  • 2023-02-14: patched
  • 2023-02-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-02-14: exploited

Related threats