Rapid7 Vulnerability & Exploit Database

Microsoft Windows: CVE-2023-21524: Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

Microsoft Windows: CVE-2023-21524: Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
01/10/2023
Created
01/11/2023
Added
01/10/2023
Modified
07/22/2024

Description

Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

Solution(s)

  • microsoft-windows-windows_10-1507-kb5022297
  • microsoft-windows-windows_10-1607-kb5022289
  • microsoft-windows-windows_10-1809-kb5022286
  • microsoft-windows-windows_10-20h2-kb5022282
  • microsoft-windows-windows_10-21h2-kb5022282
  • microsoft-windows-windows_10-22h2-kb5022282
  • microsoft-windows-windows_11-21h2-kb5022287
  • microsoft-windows-windows_11-22h2-kb5022303
  • microsoft-windows-windows_server_2022-21h2-kb5022291
  • microsoft-windows-windows_server_2022-22h2-kb5022291
  • msft-kb5022286-447ff6c5-74a0-4dfd-a497-9039e898e010
  • msft-kb5022289-e162fac6-79bd-46ee-b45c-2aa3e5451eec
  • msft-kb5022339-1b1341db-9895-4e60-a96e-84273b8dea95
  • msft-kb5022339-35777b71-2802-4f2b-91e1-e13203ba0c08
  • msft-kb5022339-40ea1718-9f50-40ac-9ada-a112d865b2cd
  • msft-kb5022339-5e9a8284-c4b5-4360-982d-bae284aed3e6
  • msft-kb5022339-80c64b1b-d72f-488c-863c-1e09185bf01c
  • msft-kb5022343-0f04bd31-ec93-4206-9552-0fee543e922e
  • msft-kb5022343-30849177-b8eb-4434-b75d-0bb1f703845f
  • msft-kb5022343-bdb9a798-4f73-4434-b83d-bc05cc7cf3e6
  • msft-kb5022346-5e7df0c9-537f-4581-9a3c-dfc8ae656196
  • msft-kb5022346-6df1459f-4045-41af-ba9d-f5502c438b49
  • msft-kb5022346-76a19426-a9ba-4152-8778-61707d85c3c1

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;