⚠ Actively exploited
Added to CISA KEV on 2024-02-29. Federal agencies required to patch by 2024-03-21. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2023-29360Untrusted Pointer Dereference in Microsoft Windows 10 Version 1607

Severity
8.4HIGHNVD
EPSS
30.3%
top 3.31%
CISA KEV
KEV
Added 2024-02-29
Due 2024-03-21
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJun 14
KEV addedFeb 29
Latest updateMar 1
KEV dueMar 21
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Microsoft Streaming Service Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.5 | Impact: 5.9

Affected Packages25 packages

NVDmicrosoft/windows< 10.0.14393.5989+2
NVDmicrosoft/windows_10_1607< 10.0.14393.5989
NVDmicrosoft/windows_10_1809< 10.0.17763.4499
NVDmicrosoft/windows_10_21h2< 10.0.19044.3086
NVDmicrosoft/windows_10_22h2< 10.0.19045.3086

Patches

🔴Vulnerability Details

3
GHSA
GHSA-mfpj-f925-v5gx: Windows TPM Device Driver Elevation of Privilege Vulnerability2023-06-14
VulnCheck
Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability2023
Project0
Project Zero RCA: CVE-2023-36802: Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

📋Vendor Advisories

2
CISA
Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability2024-02-29
Microsoft
Microsoft Streaming Service Elevation of Privilege Vulnerability2023-06-13

🕵️Threat Intelligence

5
Bleepingcomputer
CISA warns of Microsoft Streaming bug exploited in malware attacks2024-03-01
Bleepingcomputer
Raspberry Robin malware evolves with early access to Windows exploits2024-02-10
Qualys
Microsoft and Adobe Patch Tuesday, June 2023 Security Update Review | Qualys2023-06-13
Qualys
Microsoft and Adobe Patch Tuesday, June 2023 Security Update Review2023-06-13
Zscaler
Zscaler found Windows Security Vulnerabilities | 06-13-2023
CVE-2023-29360 — Untrusted Pointer Dereference | cvebase