CVE-2023-21674
published 2023-01-10CVE-2023-21674: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
PriorityP184high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-01-31
Exploited in the wild
EPSS
41.81%
98.5th percentile
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19685 | 10.0.10240.19685 |
| microsoft | windows_10_1607 | < 10.0.14393.5648 | 10.0.14393.5648 |
| microsoft | windows_10_1809 | < 10.0.17763.3887 | 10.0.17763.3887 |
| microsoft | windows_10_20h2 | < 10.0.19042.2486 | 10.0.19042.2486 |
| microsoft | windows_10_21h2 | < 10.0.19044.2486 | 10.0.19044.2486 |
| microsoft | windows_10_22h2 | < 10.0.19045.2486 | 10.0.19045.2486 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19685 | 10.0.10240.19685 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5648 | 10.0.14393.5648 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3887 | 10.0.17763.3887 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3887 | 10.0.17763.3887 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2486 | 10.0.19042.2486 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2486 | 10.0.19044.2486 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2486 | 10.0.19045.2486 |
| microsoft | windows_11_21h2 | < 10.0.22000.1455 | 10.0.22000.1455 |
| microsoft | windows_11_22h2 | < 10.0.22621.1105 | 10.0.22621.1105 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1455 | 10.0.22000.1455 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.1105 | 10.0.22621.1105 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20778 | 6.3.9600.20778 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20778 | 6.3.9600.20778 |
| microsoft | windows_server_2016 | < 10.0.14393.5648 | 10.0.14393.5648 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5648 | 10.0.14393.5648 |
| microsoft | windows_server_2019 | < 10.0.17763.3887 | 10.0.17763.3887 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3887 | 10.0.17763.3887 |
| microsoft | windows_server_2022 | < 10.0.20348.1487 | 10.0.20348.1487 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2023-21674 is actively exploited in the wild as a Windows ALPC Elevation of Privilege; it enables privilege escalation from a browser (Chromium) sandbox to SYSTEM/kernel-level privileges — monitor for sandboxed browser processes spawning privileged child processes or unexpected SYSTEM-level activity originating from browser renderer processes. ↗
- →CVE-2023-21674 is listed in CISA KEV with a remediation due date of 2023-01-31; treat any unpatched Windows system as actively at risk and prioritize detection of ALPC-based privilege escalation. ↗
- →This vulnerability class (browser sandbox EoP to SYSTEM via ALPC) is frequently chained with malware or ransomware delivery — correlate ALPC exploitation indicators with downstream malware execution or ransomware staging activity. ↗
- →Check Point IPS signature 'Microsoft Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege (CVE-2023-21674)' can be used as a detection reference for network-level IPS tuning. ↗
- ·The vulnerability was reported to Microsoft by researchers from Avast, suggesting it may have been observed in targeted threat actor activity; no specific threat actor or malware family has been publicly attributed in these sources. ↗
- ·Exploit status is confirmed as 'Exploitation Detected' in the latest software release, but the vulnerability is listed as NOT publicly disclosed — no public PoC was available at patch time, limiting community reproduction. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hqxf-h392-6m7w: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
ghsa_unreviewed·2023-01-11
CVE-2023-21674 [HIGH] CWE-416 GHSA-hqxf-h392-6m7w: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability.
VulnCheck
Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability
vulncheck·2023·CVSS 8.8
CVE-2023-21674 [HIGH] CWE-416 Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability
Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability
Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2023-Jan; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://decoded.avast.io/threatresearch/avast-q4-2022-threat-report/; https://ti.qianxin.com/uploads/2024/02/02/dcc93e586f9028c68e7ab34c3326ff31.pdf; https://www.verizon.com/business/resources/T600/reports/2024-dbir-data-breach-investi
Microsoft
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
vendor_msrc·2023-01-10·CVSS 8.8
CVE-2023-21674 [HIGH] CWE-416 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
This vulnerability could lead to a browser sandbox escape.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows ALPC: Windows ALPC
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:Yes;Latest Software Release:Exploitation Detected;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022286
Reference: https://support.
CISA
Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability
cisa·2023-01-10·CVSS 8.8
CVE-2023-21674 [HIGH] CWE-416 Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21674; https://nvd.nist.gov/vuln/detail/CVE-2023-21674
Remediation Due Date: 2023-01-31
No detection rules found.
No public exploits indexed.
Securelist
Non-mobile malware statistics, Q1 2023
blogs_securelist·2023-06-07
Non-mobile malware statistics, Q1 2023
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Most prolific groups
- Miners
- Vulnerable applications used in cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q1 2023
- IT threat evolution in Q1 2023. Non-mobile statistics
- IT threat evolution in Q1 2023. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q1 2023:
- Kaspersky solutions blocked 865,071,227 attacks launched from online resources across the globe.
- Web Anti-Virus detected 246,912,694 unique URLs.
- Attempts to run malware fo
Securelist
IT threat evolution in Q1 2023. Non-mobile statistics
blogs_securelist·2023-06-07
IT threat evolution in Q1 2023. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Attacks on Linux and VMWare ESXi servers
Progress in combating cybercrime
Conti-based Trojan decrypted
Most prolific groups
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used in cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries/territories
Checkpoint
16th January – Threat Intelligence Report
blogs_checkpoint·2023-01-16
CVE-2023-21674 16th January – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 16th January – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 16th January, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
Britain’s international mail service, Royal Mail, has had its operations disrupted by a cyberattack. The service has instructed its users not to post mail, as it is unable to dispatch packages to their destinations. The LockBit ransomware gang has been confirmed as the perpetrator of the attack, and is threatening to leak s
Krebs
Microsoft Patch Tuesday, January 2023 Edition
blogs_krebs·2023-01-10·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, January 2023 Edition
Microsoft today released updates to fix nearly 100 security flaws in its Windows operating systems and other software. Highlights from the first Patch Tuesday of 2023 include a zero-day vulnerability in Windows, printer software flaws reported by the U.S. National Security Agency, and a critical Microsoft SharePoint Server bug that allows a remote, unauthenticated attacker to make an anonymous connection.
At least 11 of the patches released today are rated “Critical” by Microsoft, meaning they could be exploited by malware or malcontents to seize remote control over vulnerable Windows systems with little or no help from users.
Of particular concern for organizations running Microsoft SharePoint Server is CVE-2023-21743. This is a Critical security bypass flaw that could allow a remote, u
Qualys
The January 2023 Patch Tuesday Security Update Review | Qualys
blogs_qualys·2023-01-10·CVSS 5.3
CVE-2023-21743 [MEDIUM] The January 2023 Patch Tuesday Security Update Review | Qualys
#### Table of Contents
- Microsoft Patches for January2023
- Adobe Patches for January2023
- Microsoft End of support Product
- Notable and Critical Microsoft Vulnerabilities Patched
- CVE-2023-21743 Microsoft SharePoint Server Security Feature Bypass Vulnerability
- CVE-2023-21763 CVE-2023-21764 Microsoft Exchange Server Elevation of Privilege Vulnerability
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Qualys Monthly Webinar Series
- This Month in Vulnerabilities & Patches
As we enter the first second Tuesday of the year, it is noteworthy that both Microsoft and Adobe have released their latest security updates and fixes. We invite you to join us as we review and
Tenable
Microsoft’s January 2023 Patch Tuesday Addresses 98 CVEs (CVE-2023-21674)
blogs_tenable·2023-01-10·CVSS 8.8
[HIGH] Microsoft’s January 2023 Patch Tuesday Addresses 98 CVEs (CVE-2023-21674)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Microsoft Patch Tuesday, January 2023 Edition
blogs_krebs·2023-01-10·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, January 2023 Edition
Microsoft today released updates to fix nearly 100 security flaws in its Windows operating systems and other software. Highlights from the first Patch Tuesday of 2023 include a zero-day vulnerability in Windows, printer software flaws reported by the U.S. National Security Agency , and a critical Microsoft SharePoint Server bug that allows a remote, unauthenticated attacker to make an anonymous connection.
At least 11 of the patches released today are rated “Critical” by Microsoft, meaning they could be exploited by malware or malcontents to seize remote control over vulnerable Windows systems with little or no help from users.
Of particular concern for organizations running Microsoft SharePoint Server is CVE-2023-21743 . This is a Critical security bypass flaw that could allow a remote,
Qualys
The January 2023 Patch Tuesday Security Update Review
blogs_qualys·2023-01-10·CVSS 5.3
CVE-2023-21743 [MEDIUM] The January 2023 Patch Tuesday Security Update Review
## Table of Contents
Microsoft Patches for January2023
Adobe Patches for January2023
Microsoft End of support Product
Notable and Critical Microsoft Vulnerabilities Patched
CVE-2023-21743 Microsoft SharePoint Server Security Feature Bypass Vulnerability
CVE-2023-21763 CVE-2023-21764 Microsoft Exchange Server Elevation of Privilege Vulnerability
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Qualys Monthly Webinar Series
This Month in Vulnerabilities & Patches
As we enter the first second Tuesday of the year, it is noteworthy that both Microsoft and Adobe have released their latest security updates and fixes. We invite you to join us as we review and discuss the p
Crowdstrike
January 2023 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] January 2023 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Zscaler
Zscaler found Windows Security Vulnerabilities | 01-10-2023
blogs_zscaler·CVSS 8.8
[HIGH] Zscaler found Windows Security Vulnerabilities | 01-10-2023
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Crowdstrike
January 2023 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] January 2023 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
2023-01-10
Published
2023-01-10
Added to CISA KEV
Exploited in the wild