Vulnerability record · CVE-2023-32046 · published 11 July 2023
CVE-2023-32046: Microsoft Windows MSHTML Platform Elevation of Privilege
Microsoft · Windows 10 1507
CVE-2023-32046 is an elevation of privilege flaw in the Windows MSHTML Platform affecting a broad range of Windows 10, Windows 11 and Windows Server releases. The record provides no root-cause detail beyond an unspecified CWE, so the exact defect is unknown, but successful exploitation lets a local attacker gain higher privileges on the host.
Description
Windows MSHTML Platform Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is confirmed exploited in the wild per CISA KEV and affects a wide range of Windows versions, though it requires local access and user interaction.
What it is
CVE-2023-32046 is an elevation of privilege flaw in the Windows MSHTML Platform affecting a broad range of Windows 10, Windows 11 and Windows Server releases. The record provides no root-cause detail beyond an unspecified CWE, so the exact defect is unknown, but successful exploitation lets a local attacker gain higher privileges on the host.
Impact
An attacker who exploits this flaw gains elevated privileges on the affected Windows system, potentially reaching SYSTEM-level rights. That level of access enables further compromise of the host, including data theft, persistence and lateral movement.
Attack surface
The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), so the attacker must already have code running on the target or convince a user to open a crafted file or link. It is not remotely reachable without that local foothold or user action.
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2023-07-11 with a remediation due date of 2023-08-01, indicating exploitation in the wild. EPSS gives a 30-day probability of about 10% (95th percentile), and CISA records no known ransomware campaign use.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for all affected Windows 10, Windows 11 and Windows Server versions.
- Prioritize patching internet-facing and high-value endpoints, and verify update installation rather than relying on scan-only reporting.
- If a system cannot be patched, follow CISA guidance to discontinue use of the product or isolate it from sensitive network segments.
- Restrict users from opening untrusted documents, links and email attachments, since exploitation requires user interaction.
- Limit local administrative rights and enforce least privilege to reduce the value of a successful elevation.
Detection
- Monitor for unexpected process creation or privilege changes consistent with local privilege escalation on patched and unpatched Windows hosts.
- Hunt for suspicious child processes spawned by browsers, Office applications or other user-facing software that handle untrusted content.
- Review Windows event logs and EDR telemetry for anomalous token or integrity-level changes on endpoints.
- Check patch-management data for hosts still missing the July 2023 Microsoft updates covering this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-32046 to the Known Exploited Vulnerabilities catalog on 11 July 2023 as "Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 1 August 2023.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32046 | PatchVendor Advisory |
| http://seclists.org/fulldisclosure/2023/Jul/43 | Broken Link |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32046 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-32046 | US Government Resource |
Track CVE-2023-32046 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-32046), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.