CVE-2023-28229CISA KEV
Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.
- Product
- Windows CNG Key Isolation Service
- Added to KEV
- 4 Oct 2023
- Federal remediation due
- 25 Oct 2023
- Known ransomware use
- Not reported