ID:9434 - Exploit for Permissions, Privileges, and Access Controls in Windows and Windows Server - CVE-2023-36427

 
Main Vulnerability Database Exploits ID:9434 - Exploit for Permissions, Privileges, and Access Controls in Windows and Windows Server - CVE-2023-36427

ID:9434 - Exploit for Permissions, Privileges, and Access Controls in Windows and Windows Server - CVE-2023-36427

Published: December 18, 2023


Vulnerability identifier: #VU83044
Vulnerability risk: Low
CVE-ID: CVE-2023-36427
CWE-ID: CWE-264
Exploitation vector: Local access
Vulnerable software:
Windows
Windows Server

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions in Windows Hyper-V, which leads to security restrictions bypass and privilege escalation.


Remediation

Install updates from vendor's website.