CVE-2023-28225HighCVSS 7.8
Windows NTLM Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What privileges could be gained by an attacker who successfully exploited the vulnerability? A domain user could use this vulnerability to elevate privileges to SYSTEM assigned integrity level.
🎯 Affected products25
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 Version 22H2 for 32-bit Systems
- Windows 10 Version 22H2 for ARM64-based Systems
- Windows 10 Version 22H2 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
✅ Remediation
KB5025229 (Security Update) — fixed build 10.0.17763.4252 KB5025230 (Security Update) — fixed build 10.0.20348.1668 KB5025221 (Security Update) — fixed build 10.0.19042.2846 KB5025224 (Security Update) — fixed build 10.0.22000.1817 KB5025221 (Security Update) — fixed build 10.0.19044.2846 KB5025239 (Security Update) — fixed build 10.0.22621.1555 KB5025221 (Security Update) — fixed build 10.0.19045.2846 KB5025234 (Security Update) — fixed build 10.0.10240.19869 KB5025228 (Security Update) — fixed build 10.0.14393.5850
🔗 References (13)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28225
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025229
- referencehttps://support.microsoft.com/help/5025229
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025230
- referencehttps://support.microsoft.com/help/5025230
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025221
- referencehttps://support.microsoft.com/help/5025221
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025224
- referencehttps://support.microsoft.com/help/5025224
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025239
- referencehttps://support.microsoft.com/help/5025239
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025234
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025228