EXPOSURES › CVE-2023-36802
CVE-2023-36802
HIGH ⌖ ON CISA KEV · EXPLOITEDA Microsoft Streaming Service Proxy vulnerability allows privilege escalation, actively exploited in the wild.
An unspecified vulnerability in Microsoft's Streaming Service Proxy enables privilege escalation, which is currently being exploited. DIB organizations using this proxy should immediately assess their exposure and apply any available mitigations to avoid unauthorized access and potential compliance violations. This highlights the importance of prompt patching and vulnerability management.
Shame score — The active exploitation of a privilege escalation vulnerability in a widely-used Microsoft product demonstrates a significant security oversight and potential for widespread compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |