EXPOSURES › CVE-2023-28229
CVE-2023-28229
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft Windows CNG Key Isolation Service privilege escalation vulnerability
Microsoft Windows CNG Key Isolation Service contains a vulnerability that allows an attacker to gain specific limited SYSTEM privileges, posing a high risk to systems running this service. DIB organizations should ensure this service is updated to mitigate the risk.
Shame score — The vulnerability is actively exploited and allows for privilege escalation, which can lead to significant security breaches.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |