CVE-2023-32046

HIGH KEV

Windows MSHTML - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-32046 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 11, 2023.

Description

Windows MSHTML Platform Elevation of Privilege Vulnerability

Scores

CVSS v3 7.8
EPSS 0.4266
EPSS Percentile 97.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2023-07-11
VulnCheck KEV 2023-07-11
InTheWild.io 2023-07-11
ENISA EUVD EUVD-2023-36333
Status published
Products (14)
microsoft/windows_10_1507 < 10.0.10240.20048
microsoft/windows_10_1607 < 10.0.14393.6085
microsoft/windows_10_1809 < 10.0.17763.4645
microsoft/windows_10_21h2 < 10.0.19041.3208
microsoft/windows_10_22h2 < 10.0.19045.3208
microsoft/windows_11_21h2 < 10.0.22000.2176
microsoft/windows_11_22h2 < 10.0.22621.1992
microsoft/windows_server_2008
microsoft/windows_server_2008 r2 sp1
microsoft/windows_server_2012
... and 4 more
Published Jul 11, 2023
KEV Added Jul 11, 2023
Tracked Since Feb 18, 2026