Junglewise Threat Intelligence

CVE-2023-29336: Microsoft Win32K Privilege Escalation Vulnerability

CVE-2023-29336 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-05-09

Technologies: Microsoft Windows Server 2008, Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Win32K, Microsoft Windows Server 2012. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability in the Microsoft Win32k kernel-mode driver allows a local attacker to gain SYSTEM privileges. The flaw is actively exploited in the wild and stems from improper memory management within the Win32k component.

Affected products

  • Microsoft Windows 10 1507, 1607
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016

Timeline

  • 2023-05-09: disclosed
  • 2023-05-09: patched
  • 2023-05-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-05-09: exploited

Related threats