Vulnerability record · CVE-2023-35628 · published 12 December 2023
CVE-2023-35628: Windows MSHTML use-after-free remote code execution
Microsoft · Windows 10 1507
CVE-2023-35628 is a use-after-free flaw in the Windows MSHTML platform that can lead to remote code execution. Microsoft rates it 8.1 (HIGH) with a network vector, and the record gives no further detail on the exact trigger or affected component. Because MSHTML is a core Windows component, unpatched systems across client and server editions are exposed.
Description
Windows MSHTML Platform Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityNetwork-reachable, no authentication or interaction required, full code execution impact, and a very high EPSS score, though KEV absence and high attack complexity keep it below critical.
What it is
CVE-2023-35628 is a use-after-free flaw in the Windows MSHTML platform that can lead to remote code execution. Microsoft rates it 8.1 (HIGH) with a network vector, and the record gives no further detail on the exact trigger or affected component. Because MSHTML is a core Windows component, unpatched systems across client and server editions are exposed.
Impact
A successful attacker can execute arbitrary code in the context of the affected process, giving full compromise of confidentiality, integrity and availability per the CVSS vector. The record does not state whether code runs at user or system privilege.
Attack surface
Reachable over the network with no privileges and no user interaction required (AV:N/PR:N/UI:N), though the high attack complexity (AC:H) implies conditions must be met for a successful trigger. The description does not specify the exact delivery path, so treat any MSHTML-rendering surface as potentially reachable.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.928 (99.8th percentile), indicating strong predicted exploitation pressure. The only references are Microsoft patch advisories, so no public exploit or in-the-wild confirmation is provided in this record.
What to do
- Apply the Microsoft December 2023 security update for CVE-2023-35628 on all listed Windows client and server versions.
- Prioritize internet-facing and user-workstation systems, then servers, since the vector is network-reachable without authentication.
- Restrict or disable MSHTML-based rendering where it is not required, and block untrusted content that reaches MSHTML.
- Verify patch deployment with a vulnerability scan or inventory check against the affected product list.
- Monitor Microsoft advisories for updated exploitation guidance given the high EPSS score.
Detection
- Hunt for MSHTML-related process crashes or unexpected child processes spawned from Office, browsers or other MSHTML hosts.
- Alert on suspicious network fetches or script execution tied to MSHTML rendering on patched-versus-unpatched hosts.
- Correlate endpoint telemetry for use-after-free indicators such as repeated crashes in mshtml.dll with subsequent code execution.
- Track patch state per host and flag any listed Windows build still missing the December 2023 update.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35628 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35628 | PatchVendor Advisory |
Track CVE-2023-35628 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-35628), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.