CVE-2023-28229
KEVmass1Windows CNG Key Isolation Service Local Privilege Escalation (CVE-2023-28229)
CISA: Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
CVE-2023-28229 is an elevation-of-privilege vulnerability in the Windows CNG Key Isolation Service (KeyIso), the component that isolates and protects private keys used for cryptographic operations on Windows. A local attacker with low privileges can trigger the flaw inside the service under specific conditions (CVSS attack complexity is high); no user interaction is required. Successful exploitation grants elevated privileges with high impact on confidentiality, integrity, and availability, effectively full control of the affected host, and is typically used to strengthen a low-privileged foothold already gained via another flaw. All supported Windows 10 releases (1507 through 22H2), Windows 11 21H2 and 22H2, and Windows Server 2008, 2012, 2016, and 2019 are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-10-04, indicating active exploitation; no public proof-of-concept is known and ransomware use is listed as unknown.
What to do: Apply Microsoft's October 2023 security updates (or later cumulative updates) on all affected Windows 10, Windows 11, and Windows Server systems, prioritizing multi-user hosts such as RDS/VDI servers and endpoints used by potentially compromised accounts, since exploitation requires local access. Verify patch status via your patch-management inventory and hunt for signs of local privilege escalation on hosts missing the fix. Note that the related KEV batch also flagged JetBrains TeamCity (CVE-2023-42793), which should be patched separately if deployed.
| microsoft Windows 10 | 1507, 1607, 1809, 20H2, 21H2, 22H2 |
| microsoft Windows 11 | 21H2, 22H2 |
| microsoft Windows Server | 2008, 2012, 2016, 2019 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows CNG Key Isolation Service
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-591
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H