CVE-2023-28293

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 11, 2023
Updated: Jan 1, 2025
CWE ID 191

Summary

CVE-2023-28293 is a newly disclosed Windows Kernel vulnerability that grants attackers elevated privileges upon successful exploitation. By leveraging this vulnerability, an attacker could potentially escalate their user-level privileges to gain system-level access. This could lead to significant security implications, including data theft, unauthorized system changes, or the installation of malware. Microsoft is actively working on a patch for this issue, and users are strongly encouraged to apply it as soon as it becomes available to protect their systems. Until then, it is recommended to practice good cybersecurity hygiene, such as avoiding suspicious emails and websites, and keeping software up to date.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share