CVE-2023-36874: Windows Error Reporting Service Elevation of Privilege Vulnerability
Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation.
Other sources
Windows Error Reporting Service Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.21063Fixed in 6.3.9600.21075Patch KB5028223 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24374Patch KB5028233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26623Patch KB5028240 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22175Patch KB5028226 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6085Patch KB5028169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20048Patch KB5028186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.3208Patch KB5028166 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1992Patch KB5028185 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.3208Patch KB5028166 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2176Patch KB5028182 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1850Patch KB5028171 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4645Patch KB5028168
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36874?
CVE-2023-36874 has been classified as a privilege escalation vulnerability in the Microsoft Windows Error Reporting Service.
How do I fix CVE-2023-36874?
To fix CVE-2023-36874, apply the relevant security updates provided by Microsoft for affected Windows products.
What systems are affected by CVE-2023-36874?
CVE-2023-36874 affects multiple versions of Windows including Windows Server 2008 R2, 2012 R2, 2016, 2019, 2022, and Windows 10 and 11.
What type of vulnerability is CVE-2023-36874?
CVE-2023-36874 is classified as an Elevation of Privilege vulnerability.
Can CVE-2023-36874 be exploited remotely?
CVE-2023-36874 requires local access for exploitation, making it less likely to be exploited remotely.