NA

CVE-2023-21752

Published: 10/01/2023 Updated: 27/04/2023
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Windows Backup Service Elevation of Privilege Vulnerability

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 10 1607

microsoft windows 7 -

microsoft windows 10 -

microsoft windows 10 1809

microsoft windows 10 20h2

microsoft windows 11 -

microsoft windows 10 21h2

microsoft windows 11 22h2

microsoft windows 10 22h2

microsoft windows 11 21h2

Github Repositories

CVE-2023-21752 PoC for arbitrary file delete vulnerability in Windows Backup service msrcmicrosoftcom/update-guide/vulnerability/CVE-2023-21752 This repo contains two exploits: v1 - Just perform file delete of user choice v2 - Tries to abuse arb delete to spawn elevated cmd shell (not very stable probably need to run it couple of times, better work on phisycal machin