CVE-2023-32046
Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability
Description
CVE-2023-32046 is an elevation of privilege vulnerability in the Microsoft Windows MSHTML platform, a core rendering engine used across multiple Windows components. This vulnerability allows an attacker to gain elevated privileges on the affected system by convincing a user to open a specially crafted file or visit a malicious website. The MSHTML platform elevation of privilege flaw affects a wide range of Microsoft Windows versions, including Windows 10, Windows 11, and Windows Server editions from 2008 through 2022. CISA has added CVE-2023-32046 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild, and with an EPSS score of 42.7%, the likelihood of exploitation remains significantly elevated.
KEV Information
CVSS Score
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows 10 1507 | < 10.0.10240.20048 |
| microsoft | windows 10 1607 | < 10.0.14393.6085 |
| microsoft | windows 10 1809 | < 10.0.17763.4645 |
| microsoft | windows 10 21h2 | < 10.0.19041.3208 |
| microsoft | windows 10 22h2 | < 10.0.19045.3208 |
| microsoft | windows 11 21h2 | < 10.0.22000.2176 |
| microsoft | windows 11 22h2 | < 10.0.22621.1992 |
| microsoft | windows server 2008 | -; r2 |
| microsoft | windows server 2012 | -; r2 |
| microsoft | windows server 2016 | - |
| microsoft | windows server 2019 | - |
| microsoft | windows server 2022 | - |
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32046(Patch, Vendor Advisory)
- http://seclists.org/fulldisclosure/2023/Jul/43(Broken Link)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-32046(US Government Resource)
Weakness Type
No specific CWE has been assigned to CVE-2023-32046 by the NVD. The vulnerability is classified as an elevation of privilege flaw in the Windows MSHTML platform, where improper handling of certain operations allows an attacker to escalate their privileges beyond the intended security boundary.
Impact Analysis
CVE-2023-32046 carries a HIGH severity rating with a CVSS v3.1 score of 7.8, reflecting its substantial risk to affected systems. The vulnerability requires local access to exploit, meaning the attacker must deliver a malicious file or lure the user to a compromised resource, and the attack complexity is low, requiring no special conditions beyond user interaction. No authentication is needed to initiate the attack, though user interaction is required — typically opening a malicious document or clicking a link. Once exploited, the impact on confidentiality, integrity, and availability is high, meaning an attacker can read sensitive data, modify system files, and disrupt services on the compromised machine. With an EPSS score of 42.7% (97th percentile), this vulnerability is among the most likely to be actively targeted by threat actors.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2023-32046 in the wild by including it in the Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of August 1, 2023. The EPSS score of 42.7% places this vulnerability in the 97th percentile, indicating a high probability of exploitation activity. While no public exploit code tagged in the NVD references is currently available, the confirmed active exploitation status means organizations should treat this as an urgent priority requiring immediate patching.
Remediation
- Apply Microsoft security updates immediately as directed by CISA's KEV required action: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Install the July 2023 Patch Tuesday updates from the Microsoft Security Update Guide.
- Prioritize patching across all affected Windows versions, including Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server (2008, 2012, 2016, 2019, 2022). Legacy systems running Windows Server 2008 or 2012 may require Extended Security Updates (ESU).
- Restrict MSHTML content execution by configuring Group Policy to disable ActiveX controls and scripting in Internet Explorer security zones, and enforce Protected View in Microsoft Office applications to prevent automatic rendering of MSHTML content from untrusted sources.
- Monitor for indicators of compromise by reviewing Windows Event Logs for suspicious process creation events, unusual privilege escalation patterns, and unexpected MSHTML rendering activity. Deploy endpoint detection rules targeting MSHTML-based exploitation techniques.
- Implement application whitelisting and email filtering to block delivery of malicious files that could trigger the MSHTML vulnerability, including enhanced filtering for Office documents and HTML-based email attachments.
Technical Details
CVE-2023-32046 exploits a flaw in the Windows MSHTML platform, the rendering engine historically associated with Internet Explorer but still embedded across numerous Windows components including Microsoft Office, Outlook, and the Windows shell. The vulnerability is triggered when MSHTML improperly handles certain objects during rendering, allowing an attacker to execute code in the security context of the current user and then elevate privileges. As reflected in the CVSS vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), exploitation requires local interaction — typically through a user opening a crafted document or visiting a malicious webpage — but no prior authentication is needed and the attack complexity is low. The scope remains unchanged, meaning the exploit operates within the compromised component's security boundary, but with high impact across all three CIA dimensions, successful exploitation grants the attacker full control over the affected system's confidentiality, integrity, and availability.
Frequently Asked Questions
Is CVE-2023-32046 being actively exploited?
Yes, CVE-2023-32046 is being actively exploited in the wild. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 1, 2023. The EPSS score of 42.7% (97th percentile) further confirms the high likelihood of exploitation.
What products are affected by CVE-2023-32046?
CVE-2023-32046 affects a broad range of Microsoft Windows operating systems. This includes Windows 10 versions 1507, 1607, 1809, 21H2, and 22H2, Windows 11 versions 21H2 and 22H2, and Windows Server editions 2008, 2012, 2016, 2019, and 2022.
How do I fix CVE-2023-32046?
Apply the July 2023 security updates from Microsoft immediately via the Microsoft Security Update Guide. As an interim measure, restrict MSHTML content execution through Group Policy and enforce Protected View in Office applications. See the Remediation section for detailed steps.
How severe is CVE-2023-32046?
CVE-2023-32046 is rated HIGH severity with a CVSS v3.1 score of 7.8 out of 10. It ranks in the 97th percentile for exploitation probability (EPSS), making it one of the more actively targeted vulnerabilities. The high impact on confidentiality, integrity, and availability means successful exploitation can grant an attacker full control of the affected system.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.