CVE-2023-21752: Windows Backup Service Elevation of Privilege Vulnerability
Published Jan 10, 2023
·Updated
Windows Backup Service Elevation of Privilege Vulnerability
Affected Software
35 affected componentsFixes available
Microsoft Windows 7
Microsoft Windows 7
Microsoft Windows 11=22H2
Microsoft Windows 11=22H2
Microsoft Windows 11=21H2
Microsoft Windows 11=21H2
Microsoft Windows 10=20H2
Microsoft Windows 10=20H2
Microsoft Windows 10=20H2
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=22H2
Microsoft Windows 10=22H2
Microsoft Windows 10=22H2
Microsoft Windows 10=1607
Microsoft Windows 10=1607
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
Microsoft Windows 10
Microsoft Windows 10
Microsoft Windows 10
Microsoft Windows 10=20h2
Microsoft Windows 10=21h2
Microsoft Windows 10=22h2
Microsoft Windows 10=1607
Microsoft Windows 10=1809
Microsoft Windows 11
Microsoft Windows 11
Microsoft Windows 11=21h2
Microsoft Windows 11=21h2
Microsoft Windows 11=22h2
Microsoft Windows 11=22h2
Microsoft Windows 7=sp1
Event History
Jan 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-21752?
CVE-2023-21752 is a vulnerability in the Windows Backup Service that allows an attacker to elevate their privileges.
2
Which software is affected by CVE-2023-21752?
Microsoft Windows 10 (all versions), Microsoft Windows 11 (all versions), and Microsoft Windows 7 with SP1 are affected by CVE-2023-21752.
3
What is the severity of CVE-2023-21752?
CVE-2023-21752 has a severity rating of 7.1 (high).
4
How do I fix CVE-2023-21752?
To fix CVE-2023-21752, apply the patches provided by Microsoft or update to the latest version of the affected software.
5
Where can I find more information about CVE-2023-21752?
You can find more information about CVE-2023-21752 on the Microsoft Security Response Center website.