CVE-2023-21746PoC(microsoft / windows_10)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Windows NTLM Elevation of Privilege Vulnerability

2.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10
  • windows_11
  • windows_7
  • windows_8.1

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Peaked 1d ago at 1 mentions (2026-03-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_10windows_11windows_7windows_8.1windows_rt_8.1windows_server_2008windows_server_2012windows_server_2016windows_server_2019windows_server_2022

7 versions affected across 10 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-07: 1Mentions · 2026-06-05: 1PoC Mentioned / Linked · 2026-03-07: 1PoC Mentioned / Linked · 2026-06-05: 103-0706-05
Signal classification1 categories
PoC
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • 計画通り@EXACASIPLANNED
    PoC

    LocalPotato自体は知っていたが、ルームを進めるのに挙動などを理解するのにとても時間がかかりましたorz https://medium.com/@farhadanwari/exploiting-lpe-on-windows-server-via-localpotato-cve-2023-21746-project-report-9de6573e96dd https://t.co/jfZLtRSB9H

    Post summary

    The tweet links to a Medium article that details how to exploit CVE‑2023‑21746 using LocalPotato, indicating a proof‑of‑concept or detailed attack guide.

    10030103
    1.4K followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    PoC

    I just completed LocalPotato room on TryHackMe! Learn how to elevate your privileges on Windows using LocalPotato (CVE-2023-21746). https://tryhackme.com/room/localpotato?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    A user shares a TryHackMe room that demonstrates privilege escalation with LocalPotato (CVE‑2023‑21746), providing a link to a proof‑of‑concept tutorial.

    0000045
CPE platform detail21 entries

21 of 21 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10---
OSmicrosoftwindows_101607--
OSmicrosoftwindows_101809--
OSmicrosoftwindows_1020h2--
OSmicrosoftwindows_1021h2--
OSmicrosoftwindows_1022h2--
OSmicrosoftwindows_11--arm64
OSmicrosoftwindows_11--x64
OSmicrosoftwindows_1121h2-arm64
OSmicrosoftwindows_1121h2-x64
OSmicrosoftwindows_1122h2-arm64
OSmicrosoftwindows_1122h2-x64
OSmicrosoftwindows_7---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---

Explore more