![Rewterz](https://rewterz.com/wp-content/uploads/2023/01/News.jpg)
![Rewterz](https://rewterz.com/wp-content/uploads/2023/01/News.jpg)
Rewterz Threat Advisory – Multiple Microsoft Windows Internet Key Exchange (IKE) Extension Vulnerabilities
January 17, 2023![Rewterz](https://rewterz.com/wp-content/uploads/2023/01/News.jpg)
Rewterz Threat Advisory – Multiple Microsoft Kernel Vulnerabilities
January 17, 2023![Rewterz](https://rewterz.com/wp-content/uploads/2023/01/News.jpg)
Rewterz Threat Advisory – Multiple Microsoft Windows Internet Key Exchange (IKE) Extension Vulnerabilities
January 17, 2023![Rewterz](https://rewterz.com/wp-content/uploads/2023/01/News.jpg)
Rewterz Threat Advisory – Multiple Microsoft Kernel Vulnerabilities
January 17, 2023Severity
Medium
Analysis Summary
CVE-2023-21559 CVSS:5.5
Microsoft Windows could allow a local authenticated attacker to obtain sensitive information, caused by a flaw in the Cryptographic component. By executing a specially-crafted program, an attacker could exploit this vulnerability to obtain Windows cryptographic secrets and then use this information to launch further attacks against the affected system.
CVE-2023-21561 CVSS:8.8
Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the Cryptographic Services component. By executing a specially-crafted program, an authenticated attacker could exploit this vulnerability to execute arbitrary code with higher privileges.
CVE-2023-21550 CVSS:5.5
Microsoft Windows could allow a local authenticated attacker to obtain sensitive information, caused by a flaw in the Cryptographic component. By executing a specially-crafted program, an attacker could exploit this vulnerability to obtain Windows cryptographic secrets and then use this information to launch further attacks against the affected system.
CVE-2023-21540 CVSS:5.5
Microsoft Windows could allow a local authenticated attacker to obtain sensitive information, caused by a flaw in the Cryptographic component. By executing a specially-crafted program, an attacker could exploit this vulnerability to obtain Windows cryptographic secrets and then use this information to launch further attacks against the affected system.
CVE-2023-21551 CVSS:7.8
Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the Cryptographic Services component. By executing a specially-crafted program, an authenticated attacker could exploit this vulnerability to obtain SYSTEM privileges.
CVE-2023-21730 CVSS:7.8
Microsoft Windows could allow a local authenticated attacker to to gain elevated privileges on the system, caused by a flaw in the Cryptographic Services. By sending a specially-crafted request, an attacker could exploit this vulnerability to gain elevated privileges.
Impact
- Information Disclosure
- Privilege Escalation
Indicators Of Compromise
CVE
- CVE-2023-21559
- CVE-2023-21561
- CVE-2023-21550
- CVE-2023-21540
- CVE-2023-21551
- CVE-2023-21730
Affected Vendors
Microsoft
Affected Products
- Microsoft Windows Server 2019
- Microsoft Windows 10 1809 for x64-based Systems
- Microsoft Windows 10 1809 for 32-bit Systems
- Microsoft Windows 10 1809 for ARM64-based Systems
- Microsoft Windows 10 20H2 for 32-bit Systems
- Microsoft Windows 10 20H2 for ARM64-based Systems
- Microsoft Windows 10 20H2 for x64-based Systems
- Microsoft Windows Server (Server Core installation) 2019
- Microsoft Windows Server 2022
- Microsoft Windows Server (Server Core installation) 2022
- Microsoft Windows 10 21H2 for 32-bit Systems
- Microsoft Windows 10 21H2 for ARM64-based Systems
- Microsoft Windows 10 21H2 for x64-based Systems
- Microsoft Windows 11 22H2 for ARM64-based Systems
- Microsoft Windows 11 22H2 for x64-based Systems
- Microsoft Windows 10 22H2 for 32-bit Systems
- Microsoft Windows 10 22H2 for ARM64-based Systems
- Microsoft Windows 10 22H2 for x64-based Systems
- Microsoft Windows 11 21H2 for ARM64-based Systems
- Microsoft Windows 11 21H2 for x64-based Systems
- Microsoft Windows Server 2022 Datacenter: Azure Edition
Remediation
Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.