Junglewise Threat Intelligence

CVE-2023-32046: Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability

CVE-2023-32046 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-07-11

Technologies: Microsoft Windows Server 2008, Microsoft Windows, Microsoft Windows Server 2016, Microsoft Windows 11, Microsoft Windows Server 2012, Microsoft Windows Server 2022, Microsoft Windows Server 2019, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

A privilege escalation vulnerability exists in the Microsoft Windows MSHTML Platform. An attacker can exploit this flaw to gain the rights of the user that is running the affected application, typically requiring the victim to open a specially crafted file or visit a malicious website.

Affected products

  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows Server 2016 -
  • Microsoft Windows Server 2019 -
  • Microsoft Windows Server 2022 -

Timeline

  • 2023-07-11: disclosed
  • 2023-07-11: patched
  • 2023-07-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-07-11: exploited: Reported as exploited in the wild at time of release.

Related threats