CVE-2023-21674

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 3 articles

EPSS Score

Source: FIRST.org · 2026-05-24
11.58%
probability
This CVE has a 11.58% probability of being exploited in the next 30 days.
0% Top 93.7th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
ALPC elevation of privilege

Attack Intelligence

Google Project Zero

Patched
Jan. 10, 2023
Reported by
Jan Vojtěšek, Milánek, and Przemek Gmerek with Avast
Root Cause Analysis
???

Exploits & PoC

hd3s5aa/CVE-2023-21674

PoC CVE-2023-21674 — hd3s5aa/CVE-2023-21674

39
1 repo — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
82%
EPSS 11.58%
Mentions 3
Last Seen Jan 11, 2023

CNA Information

Analyst Note

CVE-2023-21674 is confirmed as a legitimate Windows ALPC elevation of privilege vulnerability with a high CVSS score of 8.8, recognized by Google Project Zero and documented in CERT-EU security advisory. The classification is supported by vendor acknowledgment and credible third-party reporting, though limited public coverage (single article) and absence from CISA KEV slightly moderate absolute confidence.

Triage Info

Decided atMar 03, 2026