CVE-2023-21674Active Exploitation(microsoft / windows_10_1507)

HIGHCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-01-31. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-416

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_20h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-06-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_20h2windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2windows_rt_8.1windows_server_2012

2 versions affected across 13 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-06-28: 1Mentions · 2026-07-19: 1Mentions · 2026-07-21: 1PoC Mentioned / Linked · 2026-07-19: 1Exploit Tool / Code · 2026-07-19: 1Active Exploitation · 2026-06-28: 1Technical Details · 2026-06-28: 1Technical Details · 2026-07-19: 1Technical Details · 2026-07-21: 106-2807-1907-21
Signal classification3 categories
Active Exploitation
133.3%
Exploit
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-281
Active Exploitation1
2026-07-191
Exploit1
2026-07-211
Disclosure1
Full discourse3 posts
  • OS Dev@OSdev_
    Active Exploitation

    CVE-2023-21674 is a Windows kernel privilege escalation vulnerability in the Advanced Local Procedure Call (ALPC) subsystem. The root cause is a use-after-free. An ALPC message retains a pointer to a thread ("WaitingThread") after the thread has been freed, creating a dangling pointer that can later be dereferenced by the kernel. It was exploited in the wild and is an excellent case study in ALPC internals, thread object lifetimes, and use-after-free exploitation.

    Post summary

    CVE‑2023‑21674 is a Windows kernel privilege escalation using a use‑after‑free in ALPC that was confirmed to be exploited in the wild, though no PoC, patch, or exploit code details were provided.

    18076203.1K
    4.8K followersView on X
  • hackyboiz@hackyboiz2
    Exploit

    [Wipeload Project ⛰️ — Step 5] Chrome Full-Chain Exploitation In this article, we take the code execution we picked up from a Chrome Renderer RCE, use it to trigger CVE-2023-21674, and take the very first step toward a Sandbox Escape! Let's dive in! https://hackyboiz.github.io/2026/07/19/gongjae/Wipeload_step5/EN/ #Hackyboiz #Wipeload #ChromeFullChain #BrowserExploitation #SandboxEscape #WindowsLPE #CyberSecurity

    Post summary

    This post describes how a Chrome Renderer RCE was leveraged to trigger CVE‑2023‑21674, marking the first phase of a sandbox escape, and provides a link to a PoC detailing the exploitation steps.

    06049222.8K
    546 followersView on X
  • T1erOne@tieroneforum
    Disclosure

    Анализ ALPC Use-After-Free в ядре Windows для побега из песочницы Chrome (CVE-2023-21674) https://tier1.life/thread/424 http://tieronemkfevyizxcnt355agysp2iemvhon6iyclwrc7yuc7oszgzrid.onion/thread/424 #articles

    Post summary

    The post announces an analysis of CVE-2023-21674, a Windows kernel use-after-free that can escape Chrome’s sandbox, but it lacks any PoC, exploit tool, active exploitation evidence, or patch information.

    10041413
    314 followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_20h2---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---

Explore more