CVE-2023-29360PoC(microsoft / windows_10_1607)

LOWCVSS 8.4 · HIGHCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Microsoft Streaming Service Elevation of Privilege Vulnerability

2.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-03-21. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-822

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2windows_server_2016windows_server_2019windows_server_2022

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-15: 1PoC Mentioned / Linked · 2026-08-15: 1Technical Details · 2026-08-15: 108-15
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • hackyboiz@hackyboiz2
    PoC

    [Wipeload Project ⛰️ — Step 8] Chrome Full-Chain Exploitation Time to complete the Full Chain 🔗 In this final step, we take the Medium Integrity code execution from our Chrome Sandbox Escape, chain it with CVE-2023-29360, and abuse MDL handling in mskssrv.sys to reach SYSTEM — completing the journey from Chrome Renderer to SYSTEM! Let’s finish the chain! https://hackyboiz.github.io/2026/08/15/banda/Wipeload_step8/EN/ #Hackyboiz #Wipeload #ChromeFullChain #BrowserExploitation #SandboxEscape #WindowsLPE #CyberSecurity

    Post summary

    The post outlines the final step of a Chrome sandbox escape chain, linking a medium‑integrity code execution to CVE‑2023‑29360 and mskssrv.sys to reach SYSTEM, and supplies a link to the PoC.

    014052343.0K
    558 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---

Explore more