First published: Tue Apr 11 2023(Updated: )
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | =20H2 | |
Microsoft Windows 10 | ||
Microsoft Windows 10 | =21H2 | |
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows 10 | =20H2 | |
Microsoft Windows 10 | =20H2 | |
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | ||
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows 10 | =22H2 | |
Microsoft Windows CNG Key Isolation Service | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2019 | ||
Windows 11 | =22H2 | |
Windows 11 | =22H2 | |
Windows 11 | =21H2 | |
Windows 11 | =21H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows 10 | <10.0.10240.19869 | |
Microsoft Windows 10 | <10.0.14393.5850 | |
Microsoft Windows 10 | <10.0.17763.4252 | |
Microsoft Windows 10 | <10.0.19042.2846 | |
Microsoft Windows 10 | <10.0.19044.2846 | |
Microsoft Windows 10 | <10.0.19045.2846 | |
Windows 11 | <10.0.22000.1817 | |
Windows 11 | <10.0.22621.1555 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 | ||
<10.0.10240.19869 | ||
<10.0.14393.5850 | ||
<10.0.17763.4252 | ||
<10.0.19042.2846 | ||
<10.0.19044.2846 | ||
<10.0.19045.2846 | ||
<10.0.22000.1817 | ||
<10.0.22621.1555 | ||
=sp2 | ||
=r2-sp1 | ||
=r2 | ||
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28229 is classified as an elevation of privilege vulnerability affecting Windows CNG Key Isolation Service.
To fix CVE-2023-28229, apply the recommended patches provided by Microsoft for the affected Windows versions.
CVE-2023-28229 affects various versions of Windows including Windows 10, Windows 11, and Windows Server 2012 among others.
This vulnerability requires local access for exploitation, making it less likely to be exploited remotely.
Exploitation of CVE-2023-28229 could allow an attacker to elevate their privileges on the affected system.