CVE-2023-21678
published 2023-01-10CVE-2023-21678: Windows Print Spooler Elevation of Privilege Vulnerability
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.58%
43.9th percentile
Windows Print Spooler Elevation of Privilege Vulnerability
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19685 | 10.0.10240.19685 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5648 | 10.0.14393.5648 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3887 | 10.0.17763.3887 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3887 | 10.0.17763.3887 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2486 | 10.0.19042.2486 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2486 | 10.0.19044.2486 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2486 | 10.0.19045.2486 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1455 | 10.0.22000.1455 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.1105 | 10.0.22621.1105 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.26321 | 6.1.7601.26321 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.26321 | 6.1.7601.26321 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20778 | 6.3.9600.20778 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26321 | 6.1.7601.26321 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21872 | 6.0.6003.21872 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.24075 | 6.2.9200.24075 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20778 | 6.3.9600.20778 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5648 | 10.0.14393.5648 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3887 | 10.0.17763.3887 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1487 | 10.0.20348.1487 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_20h2 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8r23-66w7-v2h6: Windows Print Spooler Elevation of Privilege Vulnerability
ghsa_unreviewed·2023-01-11·CVSS 7.8
CVE-2023-21765 [HIGH] GHSA-8r23-66w7-v2h6: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21678, CVE-2023-21760.
GHSA
GHSA-2pwq-67gj-w45m: Windows Print Spooler Elevation of Privilege Vulnerability
ghsa_unreviewed·2023-01-11·CVSS 7.8
CVE-2023-21760 [HIGH] GHSA-2pwq-67gj-w45m: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21678, CVE-2023-21765.
GHSA
GHSA-m759-j32r-mfc8: Windows Print Spooler Elevation of Privilege Vulnerability
ghsa_unreviewed·2023-01-11·CVSS 7.1
CVE-2023-21678 [HIGH] GHSA-m759-j32r-mfc8: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21760, CVE-2023-21765.
Microsoft
Windows Print Spooler Elevation of Privilege Vulnerability
vendor_msrc·2023-01-10·CVSS 7.8
CVE-2023-21678 [HIGH] CWE-59 Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Print Spooler Components: Windows Print Spooler Components
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022286
Reference: https://support.microsoft.com/help/5022286
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022291
Reference: https://catalo
No detection rules found.
No public exploits indexed.
Tenable
Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)
blogs_tenable·2024-03-12·CVSS 8.1
[HIGH] Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Microsoft Patch Tuesday, January 2023 Edition
blogs_krebs·2023-01-10·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, January 2023 Edition
Microsoft today released updates to fix nearly 100 security flaws in its Windows operating systems and other software. Highlights from the first Patch Tuesday of 2023 include a zero-day vulnerability in Windows, printer software flaws reported by the U.S. National Security Agency, and a critical Microsoft SharePoint Server bug that allows a remote, unauthenticated attacker to make an anonymous connection.
At least 11 of the patches released today are rated “Critical” by Microsoft, meaning they could be exploited by malware or malcontents to seize remote control over vulnerable Windows systems with little or no help from users.
Of particular concern for organizations running Microsoft SharePoint Server is CVE-2023-21743. This is a Critical security bypass flaw that could allow a remote, u
Tenable
Microsoft’s January 2023 Patch Tuesday Addresses 98 CVEs (CVE-2023-21674)
blogs_tenable·2023-01-10·CVSS 8.8
[HIGH] Microsoft’s January 2023 Patch Tuesday Addresses 98 CVEs (CVE-2023-21674)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Microsoft Patch Tuesday, January 2023 Edition
blogs_krebs·2023-01-10·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, January 2023 Edition
Microsoft today released updates to fix nearly 100 security flaws in its Windows operating systems and other software. Highlights from the first Patch Tuesday of 2023 include a zero-day vulnerability in Windows, printer software flaws reported by the U.S. National Security Agency , and a critical Microsoft SharePoint Server bug that allows a remote, unauthenticated attacker to make an anonymous connection.
At least 11 of the patches released today are rated “Critical” by Microsoft, meaning they could be exploited by malware or malcontents to seize remote control over vulnerable Windows systems with little or no help from users.
Of particular concern for organizations running Microsoft SharePoint Server is CVE-2023-21743 . This is a Critical security bypass flaw that could allow a remote,
Crowdstrike
January 2023 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] January 2023 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
January 2023 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] January 2023 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
2023-01-10
Published