{"cvss":7.0,"datePublished":"2023-10-04","dateUpdated":"2023-10-04","description":"Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.","dueDate":"2023-10-25","id":"CVE-2023-28229","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28229; https://nvd.nist.gov/vuln/detail/CVE-2023-28229","product":"Windows CNG Key Isolation Service","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","severity":"HIGH","source":"cisa_known_exploited","title":"Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability","vendor":"Microsoft"}