CVE-2023-21771 is an Elevation of Privilege vulnerability in the Windows Local Session Manager (LSM) affecting Windows 10, Windows 11, and Windows Server 2022. With a CVSS score of 7.0 (HIGH), this vulnerability has a local attack vector and high attack complexity, allowing a low-privileged attacker to achieve high impact on confidentiality, integrity, and availability. While not currently listed on the KEV catalog, there is no public exploit code available, and it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:*:* | ||
21h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:*:* | ||
22h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:22h2:*:*:*:*:*:*:* | ||
21h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11:21h2:*:*:*:*:*:arm64:* | ||
21h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11:21h2:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.