CVE-2023-21800
📛 CVE Title
Windows Installer Elevation of Privilege Vulnerability
Description
Windows Installer Elevation of Privilege Vulnerability
Overview
- State
- PUBLISHED
- Assigner (CNA)
- microsoft
- CVSS severity
- HIGH
- CVSS score
- 7.8 / 10
- CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C- Effective score
- 7.8 / 10 HIGH source: CNA overview
- MSRC score
- 7.8 / 10 HIGH MS rating: Important · Elevation of Privilege
- CWE(s)
-
CWE-73 - Reserved
- 2022-12-16
- Published
- 2023-02-14 08:00 UTC
- Last updated
- 2023-02-14 08:00 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/21xxx/CVE-2023-21800.json
- Linked Threat
- CVE-2023-21800 — Windows Installer Elevation of Privilege Vulnerability
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2023-02-14 20:15:15 UTC
- NVD last modified
- 2026-06-17 05:34:01 UTC
- NVD CVSS v3.1
- 7.8 / 10 HIGH source: secure@microsoft.com
- NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Exploitability subscore
- 1.8 / 10
- Impact subscore
- 5.9 / 10
- EPSS score
- 0.0106 (probability of exploitation in next 30 days)
- EPSS percentile
- 60.95% vs all CVEs — higher = more likely to be exploited, as of 2026-07-27
NVD / KEV / EPSS data refreshed 2026-07-28 10:58 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-25967 - Assigner
- microsoft
- Published
- Feb 14, 2023, 7:33:05 PM
- Updated
- Jan 1, 2025, 12:40:57 AM
- EUVD base score (CVSS 3.1)
-
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - EUVD-reported EPSS
- 0.7200
- Vendors
- Microsoft
- Products
-
Windows Server 2008 Service Pack 2 (Server Core installation) (6.0.6003.0 <6.0.6003.21915)Windows Server 2008 Service Pack 2 (6.0.6003.0 <6.0.6003.21915)Windows Server 2008 Service Pack 2 (6.0.6003.0 <6.0.6003.21915)Windows Server 2008 R2 Service Pack 1 (Server Core installation) (6.1.7601.0 <6.1.7601.26366)Windows Server 2008 R2 Service Pack 1 (6.1.7601.0 <6.1.7601.26366)
- Aliases
-
GHSA-qqww-f8jg-rchq
ENISA description: Windows Installer Elevation of Privilege Vulnerability
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-08-11 01:49 UTC (source: CVRF).
- MS severity
- Important
- Impact
- Elevation of Privilege
- MS CVSS base score
- 7.8 / 10 (temporal 6.8)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - Exploit assessment
- Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
- Release
- 2023-Feb
Microsoft remediations / KB articles (8)
- 5022890 — Vendor Fix / Monthly Rollup (fixed build 6.0.6003.21915)
- 5022890 — Update
- 5022893 — Vendor Fix / Security Only (fixed build 6.0.6003.21915)
- 5022893 — Update
- 5022872 — Vendor Fix / Monthly Rollup (fixed build 6.1.7601.26366)
- 5022872 — Update
- 5022874 — Vendor Fix / Security Only (fixed build 6.1.7601.26366)
- 5022874 — Update
Microsoft FAQ (1)
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Affected products (5)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | Windows Server 2008 Service Pack 2 |
6.0.6003.0 (affected)
|
32-bit Systems |
| Microsoft | Windows Server 2008 Service Pack 2 (Server Core installation) |
6.0.6003.0 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Windows Server 2008 Service Pack 2 |
6.0.6003.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2008 R2 Service Pack 1 |
6.1.7601.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2008 R2 Service Pack 1 (Server Core installation) |
6.1.7601.0 (affected)
|
x64-based Systems |
Affected products — CPE 2.3 (2) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Windows Installer Elevation of Privilege Vulnerability vendor-advisory
Web references (15)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- 5022893 msrc
- 5022872 msrc
- 5022874 msrc
- 5022890 msrc
- 5022893 msrc
- MSRC update guide: CVE-2023-21800 msrc
- 5022872 msrc
- 5022874 msrc
- 5022890 msrc
- https://www.cve.org/CVERecord?id=CVE-2023-21800 rapid7:www.cve.org
- https://support.microsoft.com/en-us/help/5022872 rapid7:support.microsoft.com
- https://support.microsoft.com/en-us/help/5022874 rapid7:support.microsoft.com
- https://support.microsoft.com/en-us/help/5022890 rapid7:support.microsoft.com
- https://support.microsoft.com/en-us/help/5022893 rapid7:support.microsoft.com
- https://attackerkb.com/topics/CVE-2023-21800 rapid7:attackerkb.com
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21800 secure@microsoft.com PatchVendor Advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21800 af854a3a-2127-422b-91ae-364da2661108 PatchVendor Advisory
Remediations (17)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:www.microsoft.com
Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed.
2026-06-04 13:15 UTC -
web:tuxcare.com
It includes discovering vulnerabilities, evaluating their potential impact, prioritizing remediation efforts (including patching), and confirming the fixes. Patch Management Patch management, on the other hand, is the act of applying the necessary updates to fix known vulnerabilities. It's a critical component of vulnerability management.
2026-06-04 13:15 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-06-04 13:15 UTC -
web:techdocs.broadcom.com
Patch Category Security Patch Severity Critical Host Reboot Required Yes Virtual Machine Migration or Shutdown Required Yes Affected Hardware N/A Affected Software N/A Affected VIBs Included VMware_bootbank_esxio-update_8..3-.60.24585383 VMware_bootbank_loadesxio_8..3-.60.24585383 PRs Fixed N/A CVE numbers N/A Due to their dependency on the ...
2026-06-04 13:15 UTC -
web:www.oracle.com
This Critical Patch Update contains 374 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at October 2025 Critical Patch Update: Executive Summary and Analysis.
2026-06-04 13:15 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-06-04 13:15 UTC -
web:www.malwarebytes.com
Attackers are abusing a critical Ghost Content Management System (CMS) vulnerability to hijack more than 700 legitimate websites and inject a fake Cloudflare verification step that tricks visitors into running a Windows command that installs malware. These social engineering campaigns—where website visitors are tricked into running malicious commands on their systems—are commonly known as ...
2026-06-04 13:15 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 05:47 UTC -
web:www.pcworld.com
This month's Patch Tuesday brings over 80 fixes for various security vulnerabilities. Fortunately, none are actively being exploited in the wild yet.
2026-05-22 05:47 UTC -
web:cyberpress.org
Three critical vulnerabilities have been disclosed in n8n, the popular open-source workflow automation platform, any one of which could allow an authenticated attacker to achieve remote code execution (RCE) or read arbitrary files from the host server.
2026-05-22 05:47 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-22 05:47 UTC -
web:cybersecuritynews.com
No patch has been released yet; Microsoft has instead issued a multi-step manual mitigation guide while a formal security update is prepared. Windows BitLocker Security Bypass The vulnerability originates in WinRE's handling of the BootExecute registry value under HKLM\ControlSet001\Control\Session Manager.
2026-05-22 05:47 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 05:47 UTC -
web:windowsreport.com
It's that time of the month again: Microsoft has rolled out its Patch Tuesday updates for Windows 11 versions 23H2, 22H2, and 21H2. Windows 11 23H2 and 22H2 users will see their systems updated through KB5041585, while those on 21H2 will receive KB5041592.
2026-05-22 05:47 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.
2026-05-22 05:47 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-05-22 05:47 UTC -
web:www.notebookcheck.net
Microsoft confirmed that its April 2026 security updates, including KB5082063 and KB5083769, are triggering BitLocker recovery prompts on some Windows Server 2025, Windows 11, and Windows 10 devices.
2026-05-22 05:47 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-21800.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-21800",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-07-22T20:21:32.166421Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-07-22T20:21:36.908Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-02T09:51:51.058Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "Windows Installer Elevation of Privilege Vulnerability",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21800"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"platforms": [
"32-bit Systems"
],
"product": "Windows Server 2008 Service Pack 2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.0.6003.21915",
"status": "affected",
"version": "6.0.6003.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Windows Server 2008 Service Pack 2 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.0.6003.21915",
"status": "affected",
"version": "6.0.6003.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2008 Service Pack 2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.0.6003.21915",
"status": "affected",
"version": "6.0.6003.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2008 R2 Service Pack 1",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.1.7601.26366",
"status": "affected",
"version": "6.1.7601.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.1.7601.26366",
"status": "affected",
"version": "6.1.7601.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "6.0.6003.21915",
"versionStartIncluding": "6.0.6003.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "6.0.6003.21915",
"versionStartIncluding": "6.0.6003.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x86:*",
"versionEndExcluding": "6.0.6003.21915",
"versionStartIncluding": "6.0.6003.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "6.1.7601.26366",
"versionStartIncluding": "6.1.7601.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "6.1.7601.26366",
"versionStartIncluding": "6.1.7601.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2023-02-14T08:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Windows Installer Elevation of Privilege Vulnerability"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-73",
"description": "CWE-73: External Control of File Name or Path",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-01-01T00:40:57.470Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Windows Installer Elevation of Privilege Vulnerability",
"tags": [
"vendor-advisory"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21800"
}
],
"title": "Windows Installer Elevation of Privilege Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2023-21800",
"datePublished": "2023-02-14T19:33:05.738Z",
"dateReserved": "2022-12-16T22:13:41.239Z",
"dateUpdated": "2025-01-01T00:40:57.470Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}