Vulnerability detail
Enriched intelligence for a single CVE
High
CVE-2023-36802
PUBLISHEDMicrosoft Streaming Service Proxy Elevation of Privilege Vulnerability
- Vendor
- Microsoft
- Product
- Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2
- Published
- Sep 12, 2023
- EPSS
- —
Description
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
CVSS scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Exploitation status
Exploited in the wild
Recorded 2023-09-12 00:00:00 UTC · Source
SSVC decision points
- Exploitation
- active
- Automatable
- No
- Technical impact
- total
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | Sep 12, 2023 |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nessus | https://www.tenable.com/plugins/nessus/181313 | Jun 02, 2025 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2023-10-20 02:05:27 UTC · 35 stars
PoC for CVE-2023-36802 Microsoft Kernel Streaming Service Proxy
github · Created 2023-10-19 23:34:37 UTC · 14 stars
CVE-2023-36802 ITW case
github · Created 2023-10-09 17:32:15 UTC · 161 stars
LPE exploit for CVE-2023-36802
Timeline
-
CVE ID Reserved
-
Added to KEVIntel
-
CVE Published to Public
-
Detected by Nessus