CVE-2023-28246HighCVSS 7.8
Windows Registry Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker who successfully exploited this vulnerability could gain specific limited SYSTEM privileges.
🎯 Affected products6
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
✅ Remediation
KB5025230 (Security Update) — fixed build 10.0.20348.1668 KB5025224 (Security Update) — fixed build 10.0.22000.1817 KB5025239 (Security Update) — fixed build 10.0.22621.1555
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28246
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025230
- referencehttps://support.microsoft.com/help/5025230
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025224
- referencehttps://support.microsoft.com/help/5025224
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025239
- referencehttps://support.microsoft.com/help/5025239