CVE-2023-21725 is an Elevation of Privilege vulnerability affecting the Microsoft Windows Malicious Software Removal Tool. This vulnerability has a CVSS score of 6.3 (Medium), indicating that a low-privileged attacker could achieve high impact to integrity and availability with high attack complexity, requiring local access. There is no evidence of active exploitation, public exploit code, or Metasploit modules, and it is not listed in the CISA KEV catalog. Community discussion and media coverage are minimal, with only one article mentioning it as part of a larger patch Tuesday update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.109CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_malicious_software_removal_tool:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.109.19957.1CPE match | cpe:2.3:a:microsoft:windows_malicious_software_removal_tool:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.