CVE-2023-36721 is a Windows Error Reporting Service Elevation of Privilege vulnerability affecting multiple versions of Windows 10, 11, and Server. With a CVSS score of 7.0 (HIGH), a low-privileged attacker could achieve high impact to confidentiality, integrity, and availability if they can execute low-complexity local attacks. This vulnerability is not known to be actively exploited in the wild, nor is there publicly available exploit code in Metasploit or ExploitDB. While there's limited community discussion, it was addressed in Microsoft's October 2023 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.4974CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:* | ||
< 10.0.19041.3570CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.3570CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22000.2538CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.22621.2428CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.