Record summary

CVE-2023-21823 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2023-21823 in KEV.

Description

Windows Graphics Component Remote Code Execution Vulnerability

Description source: GitHub Advisory

Exploitation context

Known exploitation

CISA KEV
Listed · Feb 14, 2023 · CISA
VulnCheck KEV
Listed · Feb 14, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 5, 2024 · Source: CVE List

Affected products and versions

Showing 12 of 25
ProductSourceVersion rangeStatus
CVE List16.0.1 to < 16.0.16130.20156affected
CVE List16.0.1 to < 16.0.14326.21330affected
CVE List2.0.0 to < 2.70.23021003affected
CISAVersion data not supplied
CVE List10.0.10240.0 to < 10.0.10240.19747affected
CVE List10.0.14393.0 to < 10.0.14393.5717affected
CVE List10.0.17763.0 to < 10.0.17763.4010affected
10.0.0 to < 10.0.17763.4010affected
CVE List10.0.0 to < 10.0.19042.2604affected
CVE List10.0.19043.0 to < 10.0.19044.2604affected
CVE List10.0.19045.0 to < 10.0.19045.2604affected
CVE List10.0.0 to < 10.0.22621.1574affected
CVE List10.0.22621.0 to < 10.0.22621.1265affected

Proofs of concept

1

Repository PoCs

GitHubElizarfish/CVE-2023-21823Repository PoCby ElizarfishStars: 14Not analyzed2 files

4.6 KiB

GitHub

PoC details

References

3