⚠ Actively exploited
Added to CISA KEV on 2023-01-10. Federal agencies required to patch by 2023-01-31. Required action: Apply updates per vendor instructions..
CVE-2023-21674
Severity
8.8HIGH
EPSS
10.1%
top 6.89%
CISA KEV
KEV
Added 2023-01-10
Due 2023-01-31
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedJan 10
KEV addedJan 10
Latest updateJan 11
KEV dueJan 31
CISA Required Action: Apply updates per vendor instructions.
Description
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0
Affected Packages25 packages
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-hqxf-h392-6m7w: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability↗2023-01-11
CVEList
▶
VulnCheck
▶