LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-21823: Microsoft Windows Graphic Component Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 14, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 7, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-21823 to its Known Exploited Vulnerabilities catalog on Feb 14, 2023, with a federal patch deadline of Mar 7, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.

CVE-2023-21823 is a privilege escalation vulnerability in the Microsoft Windows Graphic Component. It allows an attacker who already has some level of access on a system to gain higher privileges. This matters because successful privilege escalation can let an adversary move from a limited foothold to full control of a Windows host, enabling further lateral movement, persistence, or data access. Public detail is limited; confirm all specifics against the vendor advisory.

The weakness is classified as CWE-190 (Integer Overflow or Wraparound). CISA notes that the Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation. Known ransomware use is not documented. The required action is to apply updates per vendor instructions.

How it works

CWE-190 covers integer overflow or wraparound conditions. In software that performs arithmetic on integers without proper bounds checking, a calculation can exceed the maximum value the data type can hold and wrap around to a small or negative number. When that result is later used for memory allocation, buffer sizing, indexing, or privilege-related decisions, the program can behave incorrectly.

In a privilege-escalation scenario involving a graphics component, an attacker with local access would typically supply crafted input or trigger a sequence of operations that causes the overflow. The resulting incorrect state can be abused to execute code or modify resources at a higher privilege level than the attacker originally possessed. Exact exploit mechanics for CVE-2023-21823 are not detailed in the available summary; treat the issue as a local privilege-escalation flaw in the Windows graphics stack and verify technical details only against the Microsoft advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the Graphic Component. This component is present on virtually all standard Windows desktop and server installations that support graphical rendering or related services.

Because exact affected versions are not listed in the provided facts, always cross-check the vendor advisory for the precise list of impacted Windows builds and the corresponding update packages.

How to remediate

Patch first. Apply the Microsoft security update that remediates CVE-2023-21823 according to the vendor’s instructions. Use your standard patch-management process (WSUS, Microsoft Endpoint Configuration Manager, Intune, or equivalent) to deploy the update, then verify installation on a representative sample of systems.

Confirm the exact update name and any post-install steps solely against the official Microsoft advisory.

If you can't patch immediately

Until the vendor update can be applied, reduce risk with compensating controls appropriate to a local privilege-escalation vulnerability in a core Windows component.

These measures lower likelihood and impact but do not eliminate the vulnerability. Schedule patching as soon as operationally feasible.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities can lead to full system compromise and subsequent data breaches. If you have evidence of exploitation or cannot rule it out, treat affected hosts as potentially compromised: isolate them, collect forensic artifacts, rotate credentials that may have been exposed, and follow your incident-response plan. Known ransomware use of this specific CVE is not documented, but privilege escalation is a common step in many attack chains. As a further check, you can run a free exposure scan of your email addresses against known breach data to see whether related credentials have appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-190
Added to CISA KEVFeb 14, 2023
Federal patch deadlineMar 7, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities