7
CVE-2023-28229
- EPSS 6.94%
- Published 11.04.2023 21:15:23
- Last modified 10.03.2025 20:50:17
- Source secure@microsoft.com
- Teams watchlist Login
- Open Login
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Data is provided by the National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 1507 Version < 10.0.10240.19869
Microsoft ≫ Windows 10 1607 Version < 10.0.14393.5850
Microsoft ≫ Windows 10 1809 Version < 10.0.17763.4252
Microsoft ≫ Windows 10 20h2 Version < 10.0.19042.2846
Microsoft ≫ Windows 10 21h2 Version < 10.0.19044.2846
Microsoft ≫ Windows 10 22h2 Version < 10.0.19045.2846
Microsoft ≫ Windows 11 21h2 Version < 10.0.22000.1817
Microsoft ≫ Windows 11 22h2 Version < 10.0.22621.1555
Microsoft ≫ Windows Server 2008 Version- Updatesp2
Microsoft ≫ Windows Server 2008 Versionr2 Updatesp1 HwPlatformx64
Microsoft ≫ Windows Server 2012 Version-
Microsoft ≫ Windows Server 2012 Versionr2
Microsoft ≫ Windows Server 2016 Version-
Microsoft ≫ Windows Server 2019 Version-
Microsoft ≫ Windows Server 2022 Version-
04.10.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
VulnerabilityMicrosoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.
DescriptionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Required actionsType | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 6.94% | 0.911 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
secure@microsoft.com | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-591 Sensitive Data Storage in Improperly Locked Memory
The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.