Jun 2023: Microsoft Streaming Service Elevation of Privilege Vulnerability
CVE-2023-29360 Published on June 14, 2023

Microsoft Streaming Service Elevation of Privilege Vulnerability
Microsoft Streaming Service Elevation of Privilege Vulnerability

Vendor Advisory NVD

Known Exploited Vulnerability

This Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.

The following remediation steps are recommended / required by March 21, 2024: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness Type

Untrusted Pointer Dereference

The program obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.


Products Associated with CVE-2023-29360

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 
 
 

Affected Versions

Microsoft Windows 10 Version 1809: Microsoft Windows 10 Version 1809: Microsoft Windows Server 2019: Microsoft Windows Server 2019 (Server Core installation): Microsoft Windows Server 2022: Microsoft Windows 11 version 21H2: Microsoft Windows 10 Version 21H2: Microsoft Windows 11 version 22H2: Microsoft Windows 10 Version 22H2: Microsoft Windows 10 Version 1607: Microsoft Windows Server 2016: Microsoft Windows Server 2016 (Server Core installation):

Exploit Probability

EPSS
30.82%
Percentile
96.71%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.