ZeroHour

CVE-2023-21823

KEVmass1

Actively Exploited Integer Overflow RCE in Windows Graphics Component

CISA: Microsoft Windows Graphic Component Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
6%p92
Published
()
KEV added
AI analysis

CVE-2023-21823 is an integer overflow (CWE-190) in the Microsoft Windows Graphics Component that can lead to remote code execution; CISA characterizes it as a privilege escalation flaw in the same component. Per the CVSS vector (AV:L/AC:L/PR:L/UI:N), exploitation requires an attacker to already be able to run code locally on the target — for example by getting a user to execute a malicious file — and requires only low privileges with no user interaction beyond that. A successful attack lets the adversary execute code in the context of the affected user and move on to broader actions such as malware installation, credential theft or ransomware staging. Essentially all supported Windows 10 releases (1507 through 22H2), Windows 11 21H2/22H2, and Windows Server 2008 through 2019 are affected, meaning the Windows ecosystem at large. The flaw was being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on Feb. 14, 2023, and Microsoft fixed it that day as one of three zero-days (alongside CVE-2023-21715 and CVE-2023-23376) in the February 2023 Patch Tuesday.

What to do: Apply the February 2023 Microsoft security updates (released Feb. 14, 2023) for your specific Windows 10/11 release and Windows Server version via Windows Update, WSUS, or the Microsoft Update Catalog, which is the required action under the CISA KEV listing. Prioritize systems where untrusted users can run code, such as workstations, VDI/terminal (RDS) servers and shared hosts. Confirm the patch is installed on all endpoints and review systems that were exposed while unpatched for signs of exploitation.

Affected
Microsoft Windows 101507
Microsoft Windows 101607
Microsoft Windows 101809
Microsoft Windows 1020H2
Microsoft Windows 1021H2
Microsoft Windows 1022H2
Microsoft Windows 1121H2
Microsoft Windows 1122H2
Microsoft Windows Server2008
Microsoft Windows Server2012
Microsoft Windows Server2016
Microsoft Windows Server2019
Estimated exposure
mass≈1 billion+ Windows devices (Windows 10/11 and Windows Server installations) — Windows 10 and Windows 11 have an installed base exceeding one billion active devices and Windows Server 2008–2019 remains broadly deployed in enterprise environments, so the affected population is effectively the entire supported Windows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Graphics Component Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news