CVE-2023-32046: Windows MSHTML Platform Elevation of Privilege Vulnerability
Windows MSHTML Platform Elevation of Privilege Vulnerability
Other sources
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26623Fixed in 1.001Patch KB5028167 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24374Fixed in 1.001Patch KB5028167 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22175Fixed in 1.001Patch KB5028167 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.21063Fixed in 6.3.9600.21075Fixed in 1.001Patch KB5028167 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6085Patch KB5028169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20048Patch KB5028186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.3208Patch KB5028166 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.3208Patch KB5028166 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1992Patch KB5028185 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2176Patch KB5028182 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1850Patch KB5028171 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4645Patch KB5028168 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB5028167 - Compensating control
Discontinue use of the product if updates are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32046?
CVE-2023-32046 has been rated as a critical severity vulnerability that allows elevation of privilege in affected Microsoft Windows systems.
How do I fix CVE-2023-32046?
You can mitigate CVE-2023-32046 by applying the latest security updates provided by Microsoft for your affected operating system.
Which versions of Windows are affected by CVE-2023-32046?
CVE-2023-32046 affects multiple versions of Windows, including Windows 10, Windows 11, and various Windows Server editions.
Can CVE-2023-32046 be exploited remotely?
CVE-2023-32046 can potentially be exploited locally by an attacker to elevate their privileges on the affected system.
What types of systems are vulnerable to CVE-2023-32046?
Primarily, Windows client and server systems are vulnerable, particularly those versions listed in the official Microsoft advisories.