ZeroHour

CVE-2023-36874

KEV PoC mass1

Local Privilege Escalation in Microsoft Windows Error Reporting Service

CISA: Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
43%p99
Published
()
KEV added
AI analysis

CVE-2023-36874 is a privilege escalation vulnerability in the Microsoft Windows Error Reporting Service, associated with improper handling of linked resources (CWE-59), that allows a local attacker to elevate privileges beyond their current user context. It is triggered when an attacker who can already execute code on a target Windows machine interacts with the Error Reporting Service such that the service processes attacker-influenced files or links in a way that grants it unintended access. Successful exploitation yields elevated privileges on the host, a common post-compromise step used to chain with malware or other exploits to disable defenses and move laterally. Any Windows system running the Error Reporting Service is affected — effectively all supported Windows client and server releases per CISA, though specific version ranges are not enumerated in the source data. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-07-11, confirming exploitation in the wild; no public proof-of-concept is documented, ransomware use is unknown, and EPSS estimates a 43.4% probability of exploitation within 30 days (99th percentile).

What to do: Apply the Microsoft security updates that fix CVE-2023-36874 (July 2023 Windows security updates or any later cumulative update) on all Windows endpoints and servers, prioritizing hosts where untrusted users have interactive logon (RDS/VDI, kiosks, jump servers). Because the flaw requires local access, limiting interactive logon rights on shared systems reduces risk as a compensating measure. Federal agencies must patch within CISA's standard two-week KEV remediation timeline from the 2023-07-11 listing.

Affected
Microsoft Windows
Estimated exposure
mass≈1 billion+ Windows devices (Error Reporting Service is a default OS component across supported Windows releases) — Windows' installed base exceeds one billion active devices worldwide and the Error Reporting Service ships by default on supported client and server editions, so exposure is effectively the entire Windows estate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Error Reporting Service Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news