Vulnerability record · CVE-2023-21823 · published 14 February 2023
CVE-2023-21823: Windows Graphics Component integer overflow allows local code execution
Microsoft · Windows 10 1507
CVE-2023-21823 is an integer overflow (CWE-190) in the Microsoft Windows Graphics Component that can lead to remote code execution. It affects a broad set of Windows 10, Windows 11 and Windows Server releases. The record gives only a one-line description, so the exact vulnerable function and trigger are not specified.
Description
Windows Graphics Component Remote Code Execution Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA's KEV catalog with confirmed in-the-wild exploitation and high CVSS impact, though it requires local low-privileged access rather than remote reach.
What it is
CVE-2023-21823 is an integer overflow (CWE-190) in the Microsoft Windows Graphics Component that can lead to remote code execution. It affects a broad set of Windows 10, Windows 11 and Windows Server releases. The record gives only a one-line description, so the exact vulnerable function and trigger are not specified.
Impact
An attacker who can run code on a target system can exploit the flaw to execute code at a higher integrity level, gaining the privileges of the exploited process. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The CVSS vector is AV:L/AC:L/PR:L/UI:N, so the flaw is reached locally by an attacker who already holds low privileges on the machine; no user interaction is required. It is not remotely reachable over the network in this scoring.
Exploitation
CVE-2023-21823 is listed in CISA's Known Exploited Vulnerabilities catalog with a due date of 2023-03-07, indicating exploitation in the wild. EPSS gives a 30-day probability of 0.05563 (92.5th percentile), and no ransomware campaign use is recorded.
What to do
- Apply the Microsoft security update for CVE-2023-21823 to all affected Windows 10, Windows 11 and Windows Server versions as the first action.
- Prioritize patching systems where untrusted users already have local access, such as multi-user endpoints and terminal servers.
- Restrict local logon and interactive access to only users who need it, to reduce the pool of accounts that can reach the flaw.
- Track CISA KEV remediation deadlines and confirm patching through inventory or vulnerability scanning.
Detection
- Monitor for unexpected child processes spawned by graphics-related Windows processes, which can indicate privilege escalation activity.
- Alert on local privilege escalation attempts and suspicious token or integrity-level changes in endpoint telemetry.
- Hunt for known exploitation artifacts tied to this CVE in host logs and correlate with the KEV listing.
- Verify patch state of the affected Windows builds through asset inventory rather than relying on endpoint alerts alone.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-21823 to the Known Exploited Vulnerabilities catalog on 14 February 2023 as "Microsoft Windows Graphic Component Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 March 2023.
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21823 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21823 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-21823 | US Government Resource |
Track CVE-2023-21823 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-21823), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.