CVE detail
CVE-2023-21823
Windows Graphics Component Remote Code Execution Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 13.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- 20th February – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 20th February, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHES Check Point Research identified a campaign against entities in Armenia, using a new version of OxtaRAT – an AutoIt-based backdoor for remote access and desktop surveillance. The threat actors have been targeting human […]
vendorresearch.checkpoint.comFeb 20, 2023, 4:33 PM - Week in review: Microsoft, Apple patch exploited zero-days, tips for getting hired in cybersecurityHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Combining identity and security strategies to mitigate risks The Identity Defined Security Alliance (IDSA), a nonprofit that provides vendor-neutral resources to help organizations reduce the risk of a breach by combining identity and security strategies, announced Jeff Reich as the organization’s new Executive Director. Can we predict cyber attacks? Bfore.AI says they can In this Help Net Security interview, Luigi … More →
newswww.helpnetsecurity.comFeb 19, 2023, 9:03 AM - CISA adds Cacti, Office, Windows and iOS bugs to its Known Exploited Vulnerabilities CatalogSecurity Affairs
US CISA added actively exploited flaws in Cacti framework, Microsoft Office, Windows, and iOS to its Known Exploited Vulnerabilities Catalog. US CISA added the following actively exploited flaws to its Known Exploited Vulnerabilities Catalog: CVE-2022-46169 – Cacti is an open-source platform that provides a robust and extensible operational monitoring and fault management framework for users. The flaw […]
newssecurityaffairs.comFeb 17, 2023, 5:40 AM Microsoft Patch Tuesday security updates for February 2023 addressed 75 flaws, including three actively exploited zero-day bugs. Microsoft Patch Tuesday security updates for February 2023 fixed 75 vulnerabilities in multiple products, including Microsoft Windows and Windows Components; Office and Office Components; Exchange Server; .NET Core and Visual Studio Code; 3D Builder and Print 3D; Microsoft […]
newssecurityaffairs.comFeb 14, 2023, 8:11 PM- Microsoft patches three exploited zero-days (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823)Help Net Security
The February 2023 Patch Tuesday is upon us, with Microsoft releasing patches for 75 CVE-numbered vulnerabilities, including three actively exploited zero-day flaws (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823). The three zero-days (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823) CVE-2023-21715 a vulnerability that allows attackers to bypass a Microsoft Publisher security feature: Office macro policies used to block untrusted or malicious files. “The attack itself is carried out locally by a user with authentication to the targeted system. An authenticated attacker could exploit … More →
newswww.helpnetsecurity.comFeb 14, 2023, 7:28 PM Microsoft’s Patch Tuesday machine is humming loudly with software updates to fix at least 76 vulnerabilities in Windows and OS components.
newswww.securityweek.comFeb 14, 2023, 6:38 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-24945CVSS 5.5 · Medium
Windows iSCSI Target Service Information Disclosure Vulnerability
- CVE-2023-24908CVSS 8.1 · High
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- CVE-2023-24869CVSS 8.1 · High
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- CVE-2023-23410CVSS 7.8 · High
Windows HTTP.sys Elevation of Privilege Vulnerability
- CVE-2023-23405CVSS 8.1 · High
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- CVE-2023-23385CVSS 7.0 · High
Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability