CVE-2023-32046

HIGH(7.8)KEVElevated Risk

Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability

Description

CVE-2023-32046 is an elevation of privilege vulnerability in the Microsoft Windows MSHTML platform, a core rendering engine used across multiple Windows components. This vulnerability allows an attacker to gain elevated privileges on the affected system by convincing a user to open a specially crafted file or visit a malicious website. The MSHTML platform elevation of privilege flaw affects a wide range of Microsoft Windows versions, including Windows 10, Windows 11, and Windows Server editions from 2008 through 2022. CISA has added CVE-2023-32046 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild, and with an EPSS score of 42.7%, the likelihood of exploitation remains significantly elevated.

KEV Information

Vendor
Microsoft
Product
Windows
Date Added
July 11, 2023
Due Date
August 1, 2023
Required Action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9

Affected Products

VendorProductVersion
microsoftwindows 10 1507< 10.0.10240.20048
microsoftwindows 10 1607< 10.0.14393.6085
microsoftwindows 10 1809< 10.0.17763.4645
microsoftwindows 10 21h2< 10.0.19041.3208
microsoftwindows 10 22h2< 10.0.19045.3208
microsoftwindows 11 21h2< 10.0.22000.2176
microsoftwindows 11 22h2< 10.0.22621.1992
microsoftwindows server 2008-; r2
microsoftwindows server 2012-; r2
microsoftwindows server 2016-
microsoftwindows server 2019-
microsoftwindows server 2022-

References

Weakness Type

No specific CWE has been assigned to CVE-2023-32046 by the NVD. The vulnerability is classified as an elevation of privilege flaw in the Windows MSHTML platform, where improper handling of certain operations allows an attacker to escalate their privileges beyond the intended security boundary.

Impact Analysis

CVE-2023-32046 carries a HIGH severity rating with a CVSS v3.1 score of 7.8, reflecting its substantial risk to affected systems. The vulnerability requires local access to exploit, meaning the attacker must deliver a malicious file or lure the user to a compromised resource, and the attack complexity is low, requiring no special conditions beyond user interaction. No authentication is needed to initiate the attack, though user interaction is required — typically opening a malicious document or clicking a link. Once exploited, the impact on confidentiality, integrity, and availability is high, meaning an attacker can read sensitive data, modify system files, and disrupt services on the compromised machine. With an EPSS score of 42.7% (97th percentile), this vulnerability is among the most likely to be actively targeted by threat actors.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2023-32046 in the wild by including it in the Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of August 1, 2023. The EPSS score of 42.7% places this vulnerability in the 97th percentile, indicating a high probability of exploitation activity. While no public exploit code tagged in the NVD references is currently available, the confirmed active exploitation status means organizations should treat this as an urgent priority requiring immediate patching.

Remediation

  1. Apply Microsoft security updates immediately as directed by CISA's KEV required action: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Install the July 2023 Patch Tuesday updates from the Microsoft Security Update Guide.
  2. Prioritize patching across all affected Windows versions, including Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server (2008, 2012, 2016, 2019, 2022). Legacy systems running Windows Server 2008 or 2012 may require Extended Security Updates (ESU).
  3. Restrict MSHTML content execution by configuring Group Policy to disable ActiveX controls and scripting in Internet Explorer security zones, and enforce Protected View in Microsoft Office applications to prevent automatic rendering of MSHTML content from untrusted sources.
  4. Monitor for indicators of compromise by reviewing Windows Event Logs for suspicious process creation events, unusual privilege escalation patterns, and unexpected MSHTML rendering activity. Deploy endpoint detection rules targeting MSHTML-based exploitation techniques.
  5. Implement application whitelisting and email filtering to block delivery of malicious files that could trigger the MSHTML vulnerability, including enhanced filtering for Office documents and HTML-based email attachments.

Technical Details

CVE-2023-32046 exploits a flaw in the Windows MSHTML platform, the rendering engine historically associated with Internet Explorer but still embedded across numerous Windows components including Microsoft Office, Outlook, and the Windows shell. The vulnerability is triggered when MSHTML improperly handles certain objects during rendering, allowing an attacker to execute code in the security context of the current user and then elevate privileges. As reflected in the CVSS vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), exploitation requires local interaction — typically through a user opening a crafted document or visiting a malicious webpage — but no prior authentication is needed and the attack complexity is low. The scope remains unchanged, meaning the exploit operates within the compromised component's security boundary, but with high impact across all three CIA dimensions, successful exploitation grants the attacker full control over the affected system's confidentiality, integrity, and availability.

Frequently Asked Questions

Is CVE-2023-32046 being actively exploited?

Yes, CVE-2023-32046 is being actively exploited in the wild. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 1, 2023. The EPSS score of 42.7% (97th percentile) further confirms the high likelihood of exploitation.

What products are affected by CVE-2023-32046?

CVE-2023-32046 affects a broad range of Microsoft Windows operating systems. This includes Windows 10 versions 1507, 1607, 1809, 21H2, and 22H2, Windows 11 versions 21H2 and 22H2, and Windows Server editions 2008, 2012, 2016, 2019, and 2022.

How do I fix CVE-2023-32046?

Apply the July 2023 security updates from Microsoft immediately via the Microsoft Security Update Guide. As an interim measure, restrict MSHTML content execution through Group Policy and enforce Protected View in Office applications. See the Remediation section for detailed steps.

How severe is CVE-2023-32046?

CVE-2023-32046 is rated HIGH severity with a CVSS v3.1 score of 7.8 out of 10. It ranks in the 97th percentile for exploitation probability (EPSS), making it one of the more actively targeted vulnerabilities. The high impact on confidentiality, integrity, and availability means successful exploitation can grant an attacker full control of the affected system.

CVSS Score

7.8
HIGH(7.8)

EPSS Score

EPSS Score10.05%
EPSS Percentile95.2%

Dates

PublishedJuly 11, 2023
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.