ZeroHour

CVE-2023-36802

KEVmass1

Use-After-Free Privilege Escalation in Microsoft Streaming Service Proxy

CISA: Microsoft Streaming Service Proxy Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
28%p98
Published
()
KEV added
AI analysis

CVE-2023-36802 is a use-after-free vulnerability (CWE-416) in the Microsoft Streaming Service Proxy, a component that ships with Windows, that allows an attacker to escalate privileges. It is triggered by a local attacker who can already execute code on a target machine and interacts with the streaming service proxy component in a way that mishandles freed memory. Successful exploitation typically yields elevated (SYSTEM/kernel-level) privileges, giving an attacker full control of the host and making it a common link in chained attack sequences alongside other exploits. Any Windows system carrying the affected component is potentially affected, which in practice means a very broad installed base of Windows client and server machines. The flaw is being actively exploited — CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-12 — though no public proof-of-concept is known and Microsoft's severity scoring was not yet available in the source data; EPSS estimates a high 27.5% chance of exploitation within 30 days (98th percentile).

What to do: Apply Microsoft's security updates for this vulnerability via the vendor's mitigation instructions (Windows Update/patch channel), as required by the CISA KEV listing, prioritizing internet-reachable and multi-user Windows hosts. Since exploitation requires local access, limit who can run code on Windows systems and review endpoints for signs of local privilege escalation activity; confirm the patch landed by checking installed updates against Microsoft's advisory.

Affected
Microsoft Streaming Service Proxy
Estimated exposure
mass≈hundreds of millions of Windows devices (the Streaming Service Proxy component ships with Windows, so exposure broadly mirrors the Windows install base) — The affected component is bundled with Windows rather than installed separately, so the plausible exposed population was estimated from the scale of the global Windows installed base, though only systems permitting local code execution by…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Streaming Service Proxy
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2019, windows server 2022
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news