MSRC compact vulnerability detail

CVE-2023-21804 · Windows Graphics Component Elevation of Privilege Vulnerability

No description was published by MSRC.

Severity
Important
Impact
Elevation of Privilege
CVSS
7.8 base · 6.8 temporal
Release
2023-02-14
Signals
Microsoft Graphics Component Elevation of Privilege Exploited: No Publicly disclosed: No Exploitability: Exploitation Less Likely
CWE
Patch Diff
Loading module diff metadata...
Resolved binary override
Use this when the MSRC module name cannot be mapped automatically or the resolved binary looks wrong.
Old version New version
Description
No description was published by MSRC.
FAQ / Articles
FAQ
What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Mitigation
The following mitigating factors might be helpful in your situation: Only Windows computers that have the XPS document writer feature installed are vulnerable to this exploit. On Windows 10 the XPS Document Writer is installed by default. The XPS Document Writer feature is not installed by default on Windows 11.