CVE-2023-36802

unknown KEV
Published 2023-09-12 ยท Modified 2023-09-12
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
1.5

Description

Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation.

CISA KEV

Vendor
Microsoft
Product
Streaming Service Proxy
Due date
2023-10-03

Predictions

Exploit likelihood
99%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Microsoft Security Response Center ยท View original โ†— ยท proprietary-no-redistribution
Full prose not cached โ€” VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Affected

VendorProductVersion
microsoftWindows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
microsoftWindows Server 2008 R2 for x64-based Systems Service Pack 1
microsoftWindows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
microsoftWindows Server 2012
microsoftWindows Server 2012 (Server Core installation)
microsoftWindows Server 2012 R2
microsoftWindows Server 2012 R2 (Server Core installation)
microsoftMicrosoft Visual Studio 2013 Update 5
microsoftMicrosoft Visual Studio 2015 Update 3
microsoftMicrosoft Office 2013 Service Pack 1 (32-bit editions)
microsoftMicrosoft Office 2013 Service Pack 1 (64-bit editions)
microsoftMicrosoft Office 2013 RT Service Pack 1
microsoftMicrosoft Word 2013 Service Pack 1 (32-bit editions)
microsoftMicrosoft Word 2013 Service Pack 1 (64-bit editions)
microsoftMicrosoft Word 2013 RT Service Pack 1
microsoftMicrosoft Excel 2013 Service Pack 1 (32-bit editions)
microsoftMicrosoft Excel 2013 Service Pack 1 (64-bit editions)
microsoftMicrosoft Excel 2013 RT Service Pack 1
microsoftWindows 10 for 32-bit Systems
microsoftWindows 10 for x64-based Systems
microsoftMicrosoft Excel 2016 (32-bit edition)
microsoftMicrosoft Excel 2016 (64-bit edition)
microsoftMicrosoft Word 2016 (32-bit edition)
microsoftMicrosoft Word 2016 (64-bit edition)
microsoftMicrosoft Office 2016 (32-bit edition)
microsoftMicrosoft Office 2016 (64-bit edition)
microsoftMicrosoft Outlook 2016 (32-bit edition)
microsoftMicrosoft Outlook 2016 (64-bit edition)
microsoftWindows Server 2016
microsoftWindows 10 Version 1607 for 32-bit Systems

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.