Record summary

CVE-2023-21674 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2023-21674 in KEV.

Description

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability.

Description source: GitHub Advisory

Exploitation context

Known exploitation

CISA KEV
Listed · Jan 10, 2023 · CISA
VulnCheck KEV
Listed · Jan 10, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 24, 2024 · Source: CVE List

Affected products and versions

Showing 12 of 17
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE List10.0.10240.0 to < 10.0.10240.19685affected
CVE List10.0.14393.0 to < 10.0.14393.5648affected
CVE List10.0.17763.0 to < 10.0.17763.3887affected
10.0.0 to < 10.0.17763.3887affected
CVE List10.0.0 to < 10.0.19042.2486affected
CVE List10.0.19043.0 to < 10.0.19044.2486affected
CVE List10.0.19045.0 to < 10.0.19045.2486affected
CVE List10.0.0 to < 10.0.22000.1455affected
CVE List10.0.22621.0 to < 10.0.22621.1105affected
CVE List6.3.0 to < 6.3.9600.20778affected
CVE List6.3.9600.0 to < 6.3.9600.20778affected

Windows Server 2012 R2 (Server Core installation)

Browse Microsoft / Windows Server 2012 R2 (Server Core installation)
CVE List6.3.9600.0 to < 6.3.9600.20778affected

Proofs of concept

1

Repository PoCs

GitHubhd3s5aa/CVE-2023-21674Repository PoCby hd3s5aaStars: 40Not analyzed2 files

9.2 KiB

GitHub

PoC details

References

4