CVE-2023-36874 Details
Description
Windows Error Reporting Service Elevation of Privilege Vulnerability
A vulnerability allowing elevation of privilege has been identified in the Windows Error Reporting Service. This issue arises from improper link resolution before file access, which can be exploited to gain higher privileges on the system. The vulnerability affects multiple Windows versions, including various Windows Server editions and different Windows 10 and 11 versions. Exploitation of this vulnerability allows a user to execute arbitrary code with SYSTEM privileges, particularly if the user has local administrative rights.
Users can apply the security updates provided by Microsoft to address this vulnerability. These security updates can be downloaded via the Microsoft Update Catalog or through the Windows Server Update Services (WSUS).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-36874 | CISA-ADP | US Government Resource |
| http://packetstormsecurity.com/files/174843/Microsoft-Error-Reporting-Local-Privilege-Elevation.html | CVE | ExploitThird Party AdvisoryVDB Entry |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36874 | CVE | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36874 | [email protected] | PatchVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability | Jul 11, 2023 | Aug 1, 2023 | Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft windows 10 1507 | < 10.0.10240.20048 |
CPE
Remediation
| |
| microsoft windows 10 1607 | < 10.0.14393.6085 |
CPE
Remediation
| |
| microsoft windows 10 1809 | < 10.0.17763.4645 |
CPE
Remediation
| |
| microsoft windows 10 21h2 | < 10.0.19041.3208 |
CPE
Remediation
| |
| microsoft windows 10 22h2 | < 10.0.19045.3208 |
CPE
Remediation
| |
| microsoft windows 11 21h2 | < 10.0.22000.2176 |
CPE
Remediation
| |
| microsoft windows 11 22h2 | < 10.0.22621.1992 |
CPE
Remediation
| |
| microsoft windows server 2008 | r2 sp1 |
CPE
Remediation
| |
| microsoft windows server 2012 | r2 |
CPE
Remediation
| |
| microsoft windows server 2016 | < 10.0.14393.6085 |
CPE
Remediation
| |
| microsoft windows server 2019 | < 10.0.17763.4645 |
CPE
Remediation
| |
| microsoft windows server 2022 | < 10.0.20348.1850 |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Oct 28, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Jan 23, 2025 | Modified Analysis | [email protected] |
| Jan 1, 2025 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 27, 2024 | Modified Analysis | [email protected] |
| May 29, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Sep 27, 2023 | CVE Modified | [email protected] |
| Jul 19, 2023 | Initial Analysis | [email protected] |