Summary
Microsoft Windows MSHTML Platform contains a privilege escalation flaw that was actively exploited in the wild. An attacker can trigger the vulnerable MSHTML code path by getting a victim to open a specially crafted file from email or browse a malicious website. Successful exploitation lets the attacker gain the rights of the user running the affected application.
Why Planned Fix?
4/6Exploitation Details
Gain the privileges of the user who opens the crafted file.
Privilege EscalationAffected Software
| Product | Affected Versions |
|---|---|
| Microsoft Windows | Windows 10 1507, 1607, 1809, 21H2, and 22H2; Windows 11 21H2 and 22H2; Windows Server 2008 SP2; Windows Server 2008 R2 SP1; Windows Server 2012; Windows Server 2012 R2; Windows Server 2016; Windows Server 2019; Windows Server 2022 |
Microsoft Windows is a desktop and server operating system used to run end-user workstations, servers, and built-in platform components such as the MSHTML rendering engine.
Affected ComponentMSHTML Platform privilege handling in Windows when rendering HTML content from files or websites.
MSHTML Platform privilege handling in Windows when rendering HTML content from files or websites.
Not available
Not available
Apply the Microsoft July 2023 Windows security updates for affected releases.
msrc.microsoft.comProbability of exploitation in the next 30 days
Worse than 98% of all CVEs
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Software (CPE) (14)
- •cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| msrc.microsoft.com | CVE-2023-32046 security update guide |
| nvd.nist.gov | CVE-2023-32046 Detail |
| www.cisa.gov | CISA adds five known vulnerabilities to catalog |
| www.hhs.gov | HC3 Monthly Cybersecurity Vulnerability Bulletin |
| msrc.microsoft.com | July 2023 security update |
| www.bleepingcomputer.com | Microsoft July 2023 Patch Tuesday warns of 6 zero-days, 132 flaws |
| www.tenable.com | CVE-2023-32046 |
Priority History
Initial analysis