CVE-2023-36033
- EPSS 0.2%
- Veröffentlicht 14.11.2023 18:15:32
- Zuletzt bearbeitet 23.01.2025 18:17:51
- Quelle secure@microsoft.com
- Teams Watchlist Login
- Unerledigt Login
Windows DWM Core Library Elevation of Privilege Vulnerability
14.11.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
SchwachstelleMicrosoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
BeschreibungApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Erforderliche MaßnahmenTyp | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.2% | 0.422 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
secure@microsoft.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.