LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-28229: Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 4, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 25, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-28229 to its Known Exploited Vulnerabilities catalog on Oct 4, 2023, with a federal patch deadline of Oct 25, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.

CVE-2023-28229 is a privilege-escalation vulnerability in the Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service. An attacker who already has a foothold on a system can abuse it to obtain specific limited SYSTEM privileges.

Elevation to SYSTEM-level rights can let an attacker disable defenses, access protected material, or expand control of the host. Public detail is limited to the CISA summary and the named service; confirm exact scope, affected builds, and impact against the Microsoft vendor advisory before acting.

How it works

The weakness is recorded as CWE-591 and resides in the CNG Key Isolation Service, the Windows component that isolates cryptographic keys. According to the CISA summary, the service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges. This is a local privilege-escalation class of flaw: the attacker must already be able to run code or interact with the service on the target host.

No public exploit mechanics, memory-corruption details, or proof-of-concept steps are supplied in the given facts. Defenders should treat the issue as an elevation path from a lower-privileged context to limited SYSTEM rights and obtain the precise technical description only from the vendor advisory.

Am I affected? How to find it in your systems

The CNG Key Isolation Service is a core Windows component present on modern client and server editions that use Cryptographic Next Generation features. It typically runs as a system service (often visible under the name related to key isolation or CNG) and is used whenever applications or the OS perform isolated key operations.

How to remediate

Apply the security update that Microsoft released for this CVE as soon as testing allows. The CISA required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. After patching, reboot if the advisory requires it and verify the service is running the updated binary.

If you can't patch immediately

Until the vendor update can be deployed, reduce the attack surface and increase detection.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities can lead to broader compromise and data exposure. Known ransomware use of this CVE is not documented in the supplied facts. If you suspect an attacker obtained SYSTEM rights, treat the host as potentially compromised: isolate it, collect memory and disk artifacts, rotate credentials and keys that may have been accessible, and hunt for lateral movement. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows CNG Key Isolation Service
WeaknessCWE-591
Added to CISA KEVOct 4, 2023
Federal patch deadlineOct 25, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities