CVE-2023-29336

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 4 articles

EPSS Score

Source: FIRST.org · 2026-05-24
76.66%
probability
This CVE has a 76.66% probability of being exploited in the next 30 days.
0% Top 99.0th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Win32k Elevation of Privilege

Attack Intelligence

Google Project Zero

Patched
May 9, 2023
Reported by
Jan Vojtěšek, Milánek, and Luigino Camastra with Avast
Root Cause Analysis
???

Exploits & PoC

m-cetin/CVE-2023-29336

PoC CVE-2023-29336 — m-cetin/CVE-2023-29336

21
1 repo — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
78%
EPSS 76.66%
Mentions 4
Last Seen May 10, 2023

CNA Information

Analyst Note

This Win32k elevation of privilege vulnerability in Windows 10 is confirmed by CERT-EU security advisory coverage and carries a HIGH CVSS score (7.8), indicating substantial severity. While not yet listed in CISA KEV, inclusion in Project Zero and official patch documentation from Microsoft's May 2023 update provides strong validation of the vulnerability's authenticity.

Triage Info

Decided atMar 03, 2026