CVE-2023-29360: Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability
Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
Other sources
Microsoft Streaming Service Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5989Patch KB5027219 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1848Patch KB5027231 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.3086Patch KB5027215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.3086Patch KB5027215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2057Patch KB5027223 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1787Fixed in 10.0.20348.1784Patch KB5027319 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4499Patch KB5027222 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1787Patch KB5027319 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1784Patch KB5027319 - Compensating control
Discontinue use of Microsoft Streaming Service if vendor mitigations are unavailable.
Event History
Frequently Asked Questions
What is CVE-2023-29360?
CVE-2023-29360 is a Microsoft Streaming Service Elevation of Privilege Vulnerability.
Which software products are affected by CVE-2023-29360?
Windows Server 2019, Windows Server 2016, and Windows 11 are affected by CVE-2023-29360.
What is the severity of CVE-2023-29360?
CVE-2023-29360 has a severity rating of 8.4, which is considered high.
How can I fix CVE-2023-29360 on Windows Server 2019?
To fix CVE-2023-29360 on Windows Server 2019, apply the patch provided by Microsoft. Details can be found in the remediation URL.
Where can I find more information about CVE-2023-29360?
You can find more information about CVE-2023-29360 on the Microsoft Security Response Center website.