7.8

CVE-2023-28274

Windows Win32k Elevation of Privilege Vulnerability

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 10 1809 Version < 10.0.17763.4252
MicrosoftWindows 10 20h2 Version < 10.0.19042.2846
MicrosoftWindows 10 21h2 Version < 10.0.19044.2846
MicrosoftWindows 10 22h2 Version < 10.0.19045.2846
MicrosoftWindows 11 21h2 Version < 10.0.22000.1817
MicrosoftWindows 11 22h2 Version < 10.0.22621.1555
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.71% 0.812
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
secure@microsoft.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.