KEV · Actively exploited
CVE-2023-21674
HIGH 8.8
KEV
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
EPSS
16.99%
moderate exploit risk
percentile 95.1%
CISA Known Exploited Vulnerability
- Added to KEV
- 2023-01-10
- Remediation deadline
- 2023-01-31
- Required action
- Apply updates per vendor instructions.
- Ransomware
- No
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Fixed in Windows Server 2022 (Server Core installation) 10.0.20348.1487 Windows Server 2022 10.0.20348.1487 Windows Server 2019 (Server Core installation) 10.0.17763.3887 Windows Server 2019 10.0.17763.3887 Windows Server 2016 (Server Core installation) 10.0.14393.5648 Windows Server 2016 10.0.14393.5648 Windows 11 22H2 · 2022-H2 10.0.22621.1105 Windows 11 21H2 · 2021-H2 10.0.22000.1455 Windows 10 22H2 · 2022-H2 10.0.19045.2486 Windows 10 21H2 · 2021-H2 10.0.19044.2486 Windows 10 20H2 · 2020-H2 10.0.19042.2486 Windows 10 1809 · 2018-09 10.0.17763.3887 Windows 10 1607 · 2016-07 10.0.14393.5648