CVE-2023-29336: Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Other sources
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26519Patch KB5026426 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24266Patch KB5026411 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20969Patch KB5026409 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22070Patch KB5026427 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5921Patch KB5026363 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19926Patch KB5026382
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29336?
CVE-2023-29336 has a high severity rating as it allows for privilege escalation up to SYSTEM privileges.
How do I fix CVE-2023-29336?
To fix CVE-2023-29336, apply the latest security updates provided by Microsoft for the affected Windows versions.
Which versions of Windows are affected by CVE-2023-29336?
CVE-2023-29336 affects multiple versions of Windows including Windows 10, Windows Server 2008 R2, Windows Server 2012, and Windows Server 2016.
What types of attacks can CVE-2023-29336 enable?
CVE-2023-29336 can enable attackers to escalate privileges, potentially giving them unauthorized access to system resources.
Is there a patch available for CVE-2023-29336?
Yes, Microsoft has released patches for CVE-2023-29336 that must be installed to mitigate the vulnerability.