CVE-2023-36033
- EPSS 0.72%
- Veröffentlicht 14.11.2023 18:15:32
- Zuletzt bearbeitet 28.10.2025 14:11:32
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Windows DWM Core Library Elevation of Privilege Vulnerability
14.11.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
SchwachstelleMicrosoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
BeschreibungApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.72% | 0.719 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| secure@microsoft.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.