CVE-2023-36033
- EPSS 0.2%
- Published 14.11.2023 18:15:32
- Last modified 23.01.2025 18:17:51
- Source secure@microsoft.com
- Teams watchlist Login
- Open Login
Windows DWM Core Library Elevation of Privilege Vulnerability
14.11.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
VulnerabilityMicrosoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
DescriptionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Required actionsType | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.2% | 0.422 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
secure@microsoft.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.