ZeroHour

CVE-2023-29360

KEVmass

Untrusted Pointer Dereference in Microsoft Streaming Service Grants SYSTEM Privileges

CISA: Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability

CVSS 3.1
8.4 high
EPSS
22%p98
Published
()
KEV added
AI analysis

CVE-2023-29360 is an untrusted pointer dereference (CWE-822) in the Microsoft Streaming Service, the kernel-level streaming component that ships with Windows. A local attacker who can run code on an affected system can trigger the flaw to dereference an attacker-controlled pointer, elevating their privileges from an ordinary user to SYSTEM. Successful exploitation gives the attacker full control of the host, making it a useful post-compromise step for threat actors, including in ransomware chains (CISA notes ransomware use as unknown). Any Windows system that includes the Microsoft Streaming Service is affected; the vulnerability was addressed by Microsoft's security updates in 2023. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-02-29, and EPSS estimates a 22.1% probability of exploitation in the next 30 days (98th percentile).

What to do: Apply Microsoft's June 2023 (or later) security updates on all Windows client and server hosts, per the CISA required action to apply vendor mitigations or discontinue use; there is no indication of a workaround, so patching is the primary mitigation. Prioritize systems where local privilege escalation has real impact — multi-user endpoints, RDP-exposed servers, and hosts with evidence of prior compromise — since exploitation requires local execution. Confirm patch levels against Microsoft's advisories and treat the KEV listing as a remediation deadline for your environment.

Affected
Microsoft Streaming Service (Windows kernel streaming component)
Estimated exposure
masseffectively the global Windows installed base — hundreds of millions of endpoints and servers (the streaming service kernel driver ships with Windows);… — The Microsoft Streaming Service is bundled with Windows client and server installations, so the potentially affected population is on the order of the worldwide Windows fleet, though only locally accessible systems are practically…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Streaming Service Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Streaming Service
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-822
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news