ZeroHour

CVE-2023-29336

KEV PoC mass1

Use-after-free privilege escalation to SYSTEM in Microsoft Win32k

CISA: Microsoft Win32K Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
41%p99
Published
()
KEV added
AI analysis

CVE-2023-29336 is a use-after-free flaw (CWE-416) in Microsoft's Win32k kernel component that allows privilege escalation to SYSTEM. It is triggered by code running on a Windows host that causes the Win32k driver to reference freed kernel memory; the exact trigger path is not detailed in the available data, but as a kernel elevation-of-privilege issue it requires local code execution or an attacker already holding a foothold on the machine. A successful exploit grants SYSTEM privileges, giving the attacker full control of the compromised host. Because Win32k ships in every supported Windows client and server, effectively the entire Windows installed base is exposed to the flaw. The vulnerability is confirmed exploited in the wild — CISA added it to the KEV catalog on 2023-05-09 — and EPSS places its 30-day exploitation probability at 40.9% (99th percentile), though no public proof-of-concept is known and ransomware use is unconfirmed.

What to do: Apply Microsoft's current cumulative Windows security updates (issued May 2023, per the CISA KEV required action) across all Windows clients and servers, prioritizing servers and systems exposed to untrusted users since the flaw is being actively exploited. Until patched, limit untrusted local code execution and restrict remote entry points such as RDP, because local privilege escalation flaws are commonly chained into full compromises. Verify update installation after deployment; specific affected build numbers and any ransomware involvement are not stated in the available data.

Affected
Microsoft Win32k
Estimated exposure
mass≈1 billion+ Windows devices (Win32k ships in every supported Windows client and server) — Win32k is a core kernel component included in all supported Windows editions and the Windows installed base is publicly estimated at more than a billion devices, so virtually every Windows host is plausibly affected; the count of actually…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Win32k Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows server 2008, windows server 2012, windows server 2016
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news