← back
CVE-2023-28229

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CVSS 7 HIGHEPSS 1.9%● KEVCWE-591
In short

A vulnerability in Windows CNG Key Isolation Service allows an attacker with local access to gain higher privileges on the system. This could let them take control of sensitive cryptographic operations and access protected data.

Technical detail

Local elevation of privilege vulnerability in the CNG Key Isolation Service due to improper privilege management (CWE-591). An authenticated attacker can exploit this to escalate privileges without user interaction, potentially gaining SYSTEM-level access to cryptographic key material and protected resources.

Summary generated and translated by AI from the official description.
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →