ZeroHour

CVE-2023-28229

KEVmass1

Windows CNG Key Isolation Service Local Privilege Escalation (CVE-2023-28229)

CISA: Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

CVSS 3.1
7.0 high
EPSS
2%p76
Published
()
KEV added
AI analysis

CVE-2023-28229 is an elevation-of-privilege vulnerability in the Windows CNG Key Isolation Service (KeyIso), the component that isolates and protects private keys used for cryptographic operations on Windows. A local attacker with low privileges can trigger the flaw inside the service under specific conditions (CVSS attack complexity is high); no user interaction is required. Successful exploitation grants elevated privileges with high impact on confidentiality, integrity, and availability, effectively full control of the affected host, and is typically used to strengthen a low-privileged foothold already gained via another flaw. All supported Windows 10 releases (1507 through 22H2), Windows 11 21H2 and 22H2, and Windows Server 2008, 2012, 2016, and 2019 are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-10-04, indicating active exploitation; no public proof-of-concept is known and ransomware use is listed as unknown.

What to do: Apply Microsoft's October 2023 security updates (or later cumulative updates) on all affected Windows 10, Windows 11, and Windows Server systems, prioritizing multi-user hosts such as RDS/VDI servers and endpoints used by potentially compromised accounts, since exploitation requires local access. Verify patch status via your patch-management inventory and hunt for signs of local privilege escalation on hosts missing the fix. Note that the related KEV batch also flagged JetBrains TeamCity (CVE-2023-42793), which should be patched separately if deployed.

Affected
microsoft Windows 101507, 1607, 1809, 20H2, 21H2, 22H2
microsoft Windows 1121H2, 22H2
microsoft Windows Server2008, 2012, 2016, 2019
Estimated exposure
mass1 billion+ Windows devices (essentially the entire supported Windows 10/11 client base plus Windows Server 2008-2019) — Every supported Windows client and server release in the data is in scope, and Windows 10/11 alone runs on well over a billion active devices worldwide, so the potentially affected installed base is of billion-plus magnitude.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows CNG Key Isolation Service
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-591
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news