⚠ Actively exploited
Added to CISA KEV on 2023-09-12. Federal agencies required to patch by 2023-10-03. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2023-36802Use After Free in Microsoft Windows 10 Version 1809

CWE-416Use After Free24 documents14 sources
Severity
7.8HIGHNVD
EPSS
75.4%
top 1.10%
CISA KEV
KEV
Added 2023-09-12
Due 2023-10-03
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedSep 12
KEV addedSep 12
KEV dueOct 3
Latest updateDec 6
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages28 packages

NVDmicrosoft/windows< 10.0.17763.4851+1
NVDmicrosoft/windows_10_1809< 10.0.17763.4851
NVDmicrosoft/windows_10_21h2< 10.0.19044.3448
NVDmicrosoft/windows_10_22h2< 10.0.19045.3448
NVDmicrosoft/windows_11_21h2< 10.0.22000.2416

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4v34-9x49-p452: Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability2023-09-12
VulnCheck
Microsoft Streaming Service Proxy Privilege Escalation Vulnerability2023
Project0
Project Zero RCA: CVE-2023-36802: Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

📋Vendor Advisories

2
Microsoft
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability2023-09-12
CISA
Microsoft Streaming Service Proxy Privilege Escalation Vulnerability2023-09-12

🕵️Threat Intelligence

18
Securelist
Exploits and vulnerabilities in Q3 20242024-12-06
Securelist
Analyzing the vulnerability landscape in Q3 20242024-12-06
Tenable
Microsoft’s June 2024 Patch Tuesday Addresses 49 CVEs2024-06-11
Bleepingcomputer
Raspberry Robin malware evolves with early access to Windows exploits2024-02-10
Tenable
Microsoft’s November 2023 Patch Tuesday Addresses 57 CVEs (CVE-2023-36025)2023-11-14
CVE-2023-36802 — Use After Free in Microsoft | cvebase