CVE-2023-21817
📛 CVE Title
Windows Kerberos Elevation of Privilege Vulnerability
Description
Windows Kerberos Elevation of Privilege Vulnerability
Overview
- State
- PUBLISHED
- Assigner (CNA)
- microsoft
- CVSS severity
- HIGH
- CVSS score
- 7.8 / 10
- CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C- Effective score
- 7.8 / 10 HIGH source: CNA overview
- MSRC score
- 7.8 / 10 HIGH MS rating: Important · Elevation of Privilege
- CWE(s)
-
CWE-287 - Reserved
- 2022-12-16
- Published
- 2023-02-14 08:00 UTC
- Last updated
- 2023-02-14 08:00 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/21xxx/CVE-2023-21817.json
- Linked Threat
- CVE-2023-21817 — Windows Kerberos Elevation of Privilege Vulnerability
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-25983 - Assigner
- microsoft
- Published
- Feb 14, 2023, 7:33:19 PM
- Updated
- Jan 1, 2025, 12:41:04 AM
- EUVD base score (CVSS 3.1)
-
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - EUVD-reported EPSS
- 1.0700
- Vendors
- Microsoft
- Products
-
Windows Server 2008 Service Pack 2 (6.0.6003.0 <6.0.6003.21915)Windows Server 2016 (Server Core installation) (10.0.14393.0 <10.0.14393.5717)Windows Server 2022 (10.0.20348.0 <10.0.20348.1547)Windows Server 2012 R2 (Server Core installation) (6.3.9600.0 <6.3.9600.20821)Windows 10 Version 1607 (10.0.14393.0 <10.0.14393.5717)Windows 10 Version 22H2 (10.0.19045.0 <10.0.19045.2604)Windows Server 2008 R2 Service Pack 1 (Server Core installation) (6.1.7601.0 <6.1.7601.26366)Windows 10 Version 20H2 (10.0.0 <10.0.19042.2604)Windows Server 2008 Service Pack 2 (Server Core installation) (6.0.6003.0 <6.0.6003.21915)Windows 11 version 22H2 (10.0.22621.0 <10.0.22621.1265)Windows 10 Version 1809 (10.0.17763.0 <10.0.17763.4010)Windows Server 2012 R2 (6.3.9600.0 <6.3.9600.20821)Windows Server 2019 (10.0.17763.0 <10.0.17763.4010)Windows 10 Version 21H2 (10.0.19043.0 <10.0.19044.2604)Windows Server 2012 (6.2.9200.0 <6.2.9200.24116)Windows Server 2012 (Server Core installation) (6.2.9200.0 <6.2.9200.24116)Windows Server 2019 (Server Core installation) (10.0.17763.0 <10.0.17763.4010)Windows 10 Version 1809 (10.0.0 <10.0.17763.4010)Windows Server 2016 (10.0.14393.0 <10.0.14393.5717)Windows Server 2008 R2 Service Pack 1 (6.1.7601.0 <6.1.7601.26366)Windows 11 version 21H2 (10.0.0 <10.0.22621.1574)Windows Server 2008 Service Pack 2 (6.0.6003.0 <6.0.6003.21915)Windows 10 Version 1507 (10.0.10240.0 <10.0.10240.19747)
- Aliases
-
GHSA-4w7x-2jcw-qr33
ENISA description: Windows Kerberos Elevation of Privilege Vulnerability
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-08-11 01:49 UTC (source: CVRF).
- MS severity
- Important
- Impact
- Elevation of Privilege
- MS CVSS base score
- 7.8 / 10 (temporal 6.8)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - Exploit assessment
- Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
- Release
- 2023-Feb
Microsoft remediations / KB articles (28)
- 5022840 — Vendor Fix / Security Update (fixed build 10.0.17763.4010)
- 5022840 — Update
- 5022842 — Vendor Fix / Security Update (fixed build 10.0.20348.1547)
- 5022842 — Update
- 5022921 — Vendor Fix / Security Hotpatch Update (fixed build 10.0.20348.1540)
- 5022834 — Vendor Fix / Security Update (fixed build 10.0.19042.2604)
- 5022834 — Update
- 5022836 — Vendor Fix / Security Update (fixed build 10.0.22621.1574)
- 5022845 — Vendor Fix / Security Update (fixed build 10.0.22621.1265)
- 5022845 — Update
- 5022858 — Vendor Fix / Security Update (fixed build 10.0.10240.19747)
- 5022838 — Vendor Fix / Security Update (fixed build 10.0.14393.5717)
- 5022890 — Vendor Fix / Monthly Rollup (fixed build 6.0.6003.21915)
- 5022890 — Update
- 5022893 — Vendor Fix / Security Only (fixed build 6.0.6003.21915)
- 5022893 — Update
- 5022872 — Vendor Fix / Monthly Rollup (fixed build 6.1.7601.26366)
- 5022872 — Update
- 5022874 — Vendor Fix / Security Only (fixed build 6.1.7601.26366)
- 5022874 — Update
- 5022903 — Vendor Fix / Monthly Rollup (fixed build 6.2.9200.24116)
- 5022903 — Update
- 5022895 — Vendor Fix / Security Only (fixed build 6.2.9200.24116)
- 5022895 — Update
- 5022899 — Vendor Fix / Monthly Rollup (fixed build 6.3.9600.20821)
- 5022899 — Update
- 5022894 — Vendor Fix / Security Only (fixed build 6.3.9600.20821)
- 5022894 — Update
Microsoft FAQ (1)
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Affected products (23)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | Windows 10 Version 1809 |
10.0.17763.0 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Windows 10 Version 1809 |
10.0.0 (affected)
|
ARM64-based Systems |
| Microsoft | Windows Server 2019 |
10.0.17763.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2019 (Server Core installation) |
10.0.17763.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2022 |
10.0.20348.0 (affected)
|
x64-based Systems |
| Microsoft | Windows 10 Version 20H2 |
10.0.0 (affected)
|
32-bit Systems, ARM64-based Systems |
| Microsoft | Windows 11 version 21H2 |
10.0.0 (affected)
|
x64-based Systems, ARM64-based Systems |
| Microsoft | Windows 10 Version 21H2 |
10.0.19043.0 (affected)
|
32-bit Systems, ARM64-based Systems, x64-based Systems |
| Microsoft | Windows 11 version 22H2 |
10.0.22621.0 (affected)
|
ARM64-based Systems, x64-based Systems |
| Microsoft | Windows 10 Version 22H2 |
10.0.19045.0 (affected)
|
x64-based Systems, ARM64-based Systems, 32-bit Systems |
| Microsoft | Windows 10 Version 1507 |
10.0.10240.0 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Windows 10 Version 1607 |
10.0.14393.0 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Windows Server 2016 |
10.0.14393.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2016 (Server Core installation) |
10.0.14393.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2008 Service Pack 2 |
6.0.6003.0 (affected)
|
32-bit Systems |
| Microsoft | Windows Server 2008 Service Pack 2 (Server Core installation) |
6.0.6003.0 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Windows Server 2008 Service Pack 2 |
6.0.6003.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2008 R2 Service Pack 1 |
6.1.7601.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2008 R2 Service Pack 1 (Server Core installation) |
6.1.7601.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2012 |
6.2.9200.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2012 (Server Core installation) |
6.2.9200.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2012 R2 |
6.3.9600.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2012 R2 (Server Core installation) |
6.3.9600.0 (affected)
|
x64-based Systems |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Windows Kerberos Elevation of Privilege Vulnerability vendor-advisory
Web references (28)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- 5022834 msrc
- 5022836 msrc
- 5022838 msrc
- 5022840 msrc
- 5022842 msrc
- 5022845 msrc
- 5022858 msrc
- 5022872 msrc
- 5022874 msrc
- 5022890 msrc
- 5022893 msrc
- 5022894 msrc
- 5022895 msrc
- 5022899 msrc
- 5022903 msrc
- MSRC update guide: CVE-2023-21817 msrc
- 5022834 msrc
- 5022840 msrc
- 5022842 msrc
- 5022845 msrc
- 5022872 msrc
- 5022874 msrc
- 5022890 msrc
- 5022893 msrc
- 5022894 msrc
- 5022895 msrc
- 5022899 msrc
- 5022903 msrc
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:www.bleepingcomputer.com
CISA has ordered government agencies to secure their systems against a high-severity Oracle WebLogic Server vulnerability that was patched two years ago and is now actively exploited in attacks.
2026-06-04 14:45 UTC -
web:www.esri.com
Key highlights The ArcGIS Server Security 2025 update 2 is available This patch resolves 10 Medium severity vulnerabilities This security patch is cumulative, and includes fixes provided in the ArcGIS Server Security 2025 update 1.
2026-06-04 14:45 UTC -
web:gemini.google.com
Meet Gemini, Google's AI assistant. Get help with writing, planning, brainstorming, and more. Experience the power of generative AI.
2026-06-04 14:45 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-04 14:45 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-06-04 14:45 UTC -
web:docs.tenable.com
Remediation and mitigation plans should be created based-off prioritization plans. Most legacy methods employ the CVSS to prioritize which vulnerabilities to remediate first. For example, a typical organizational policy is to remediate all vulnerabilities with a CVSS score of 7 and above.
2026-06-04 14:45 UTC -
web:nvd.nist.gov
The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...
2026-06-04 14:45 UTC -
web:attack.mitre.org
This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...
2026-06-04 14:45 UTC -
web:www.secure.com
Learn the difference between vulnerability remediation and mitigation , and how a risk-based strategy can strengthen your security posture.
2026-05-22 05:47 UTC -
web:www.securityweek.com
Microsoft has announced mitigations for CVE -2026-45585, a BitLocker bypass triggered via FsTx in Windows Recovery.
2026-05-22 05:47 UTC -
web:www.zdnet.com
Install Microsoft's emergency Windows patch now - what it fixes and why it was rushed out Microsoft issued an out-of-band fix after its latest update introduced a nasty surprise.
2026-05-22 05:47 UTC -
web:cybersecuritynews.com
No patch has been released yet; Microsoft has instead issued a multi-step manual mitigation guide while a formal security update is prepared. Windows BitLocker Security Bypass The vulnerability originates in WinRE's handling of the BootExecute registry value under HKLM\ControlSet001\Control\Session Manager.
2026-05-22 05:47 UTC -
web:github.com
A patch that fixes various issues in the PC port of Alice: Madness Returns.
2026-05-22 05:47 UTC -
web:petri.com
Microsoft's December 2025 Patch Tuesday delivers 56 security fixes and key improvements for Windows 11.
2026-05-22 05:47 UTC -
web:windowsreport.com
It's that time of the month again: Microsoft has rolled out its Patch Tuesday updates for Windows 11 versions 23H2, 22H2, and 21H2. Windows 11 23H2 and 22H2 users will see their systems updated through KB5041585, while those on 21H2 will receive KB5041592.
2026-05-22 05:47 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.
2026-05-22 05:47 UTC -
web:www.experts-exchange.com
Learn more about Resolving Sweet32, Birthday Attacks on Windows Servers Via GPO from the expert community at Experts Exchange
2026-05-22 05:47 UTC -
web:www.microsoft.com
Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed.
2026-05-22 05:47 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-21817.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-21817",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-06-11T03:56:01.814440Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-11T13:43:25.949Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-02T09:51:51.283Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "Windows Kerberos Elevation of Privilege Vulnerability",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21817"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Windows 10 Version 1809",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.17763.4010",
"status": "affected",
"version": "10.0.17763.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"ARM64-based Systems"
],
"product": "Windows 10 Version 1809",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.17763.4010",
"status": "affected",
"version": "10.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2019",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.17763.4010",
"status": "affected",
"version": "10.0.17763.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2019 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.17763.4010",
"status": "affected",
"version": "10.0.17763.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2022",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.20348.1547",
"status": "affected",
"version": "10.0.20348.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"ARM64-based Systems"
],
"product": "Windows 10 Version 20H2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.19042.2604",
"status": "affected",
"version": "10.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems",
"ARM64-based Systems"
],
"product": "Windows 11 version 21H2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.22621.1574",
"status": "affected",
"version": "10.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"ARM64-based Systems",
"x64-based Systems"
],
"product": "Windows 10 Version 21H2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.19044.2604",
"status": "affected",
"version": "10.0.19043.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"ARM64-based Systems",
"x64-based Systems"
],
"product": "Windows 11 version 22H2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.22621.1265",
"status": "affected",
"version": "10.0.22621.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems",
"ARM64-based Systems",
"32-bit Systems"
],
"product": "Windows 10 Version 22H2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.19045.2604",
"status": "affected",
"version": "10.0.19045.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Windows 10 Version 1507",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.10240.19747",
"status": "affected",
"version": "10.0.10240.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Windows 10 Version 1607",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.14393.5717",
"status": "affected",
"version": "10.0.14393.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2016",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.14393.5717",
"status": "affected",
"version": "10.0.14393.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2016 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.14393.5717",
"status": "affected",
"version": "10.0.14393.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems"
],
"product": "Windows Server 2008 Service Pack 2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.0.6003.21915",
"status": "affected",
"version": "6.0.6003.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Windows Server 2008 Service Pack 2 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.0.6003.21915",
"status": "affected",
"version": "6.0.6003.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2008 Service Pack 2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.0.6003.21915",
"status": "affected",
"version": "6.0.6003.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2008 R2 Service Pack 1",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.1.7601.26366",
"status": "affected",
"version": "6.1.7601.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.1.7601.26366",
"status": "affected",
"version": "6.1.7601.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2012",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.2.9200.24116",
"status": "affected",
"version": "6.2.9200.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2012 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.2.9200.24116",
"status": "affected",
"version": "6.2.9200.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2012 R2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.3.9600.20821",
"status": "affected",
"version": "6.3.9600.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2012 R2 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "6.3.9600.20821",
"status": "affected",
"version": "6.3.9600.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"versionEndExcluding": "10.0.17763.4010",
"versionStartIncluding": "10.0.17763.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:arm64:*",
"versionEndExcluding": "10.0.17763.4010",
"versionStartIncluding": "10.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.0.17763.4010",
"versionStartIncluding": "10.0.17763.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.0.17763.4010",
"versionStartIncluding": "10.0.17763.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.0.20348.1547",
"versionStartIncluding": "10.0.20348.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_20H2:*:*:*:*:*:*:x86:*",
"versionEndExcluding": "10.0.19042.2604",
"versionStartIncluding": "10.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_21H2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "10.0.22621.1574",
"versionStartIncluding": "10.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*",
"versionEndExcluding": "10.0.19044.2604",
"versionStartIncluding": "10.0.19043.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_22H2:*:*:*:*:*:*:arm64:*",
"versionEndExcluding": "10.0.22621.1265",
"versionStartIncluding": "10.0.22621.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "10.0.19045.2604",
"versionStartIncluding": "10.0.19045.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
"versionEndExcluding": "10.0.10240.19747",
"versionStartIncluding": "10.0.10240.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"versionEndExcluding": "10.0.14393.5717",
"versionStartIncluding": "10.0.14393.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.0.14393.5717",
"versionStartIncluding": "10.0.14393.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.0.14393.5717",
"versionStartIncluding": "10.0.14393.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "6.0.6003.21915",
"versionStartIncluding": "6.0.6003.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "6.0.6003.21915",
"versionStartIncluding": "6.0.6003.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x86:*",
"versionEndExcluding": "6.0.6003.21915",
"versionStartIncluding": "6.0.6003.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "6.1.7601.26366",
"versionStartIncluding": "6.1.7601.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "6.1.7601.26366",
"versionStartIncluding": "6.1.7601.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "6.2.9200.24116",
"versionStartIncluding": "6.2.9200.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "6.2.9200.24116",
"versionStartIncluding": "6.2.9200.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "6.3.9600.20821",
"versionStartIncluding": "6.3.9600.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "6.3.9600.20821",
"versionStartIncluding": "6.3.9600.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2023-02-14T08:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Windows Kerberos Elevation of Privilege Vulnerability"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287: Improper Authentication",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-01-01T00:41:04.434Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Windows Kerberos Elevation of Privilege Vulnerability",
"tags": [
"vendor-advisory"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21817"
}
],
"title": "Windows Kerberos Elevation of Privilege Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2023-21817",
"datePublished": "2023-02-14T19:33:19.202Z",
"dateReserved": "2022-12-16T22:13:41.244Z",
"dateUpdated": "2025-01-01T00:41:04.434Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}