CVE-2023-36033 is an Elevation of Privilege vulnerability in the Windows DWM Core Library, affecting various versions of Windows 10, 11, and Server. With a CVSS score of 7.8 (HIGH), it allows a local attacker to achieve high impact on confidentiality, integrity, and availability with low attack complexity and no user interaction. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered significant community discussion and media coverage. Despite active exploitation, public exploit code such as Metasploit modules or ExploitDB entries are not currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.5122CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:arm64:* | ||
< 10.0.17763.5122CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.5122CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19041.3693CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.19041.3693CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.