CVE-2023-36802Exploit(microsoft / windows_10_1809)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft windows_10_1809 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-10-03. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2
  • windows_11_21h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 2 mentions (2026-06-24); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1809windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2windows_server_2019windows_server_2022

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-24: 2Mentions · 2026-06-27: 1PoC Mentioned / Linked · 2026-06-24: 2PoC Mentioned / Linked · 2026-06-27: 1Exploit Tool / Code · 2026-06-24: 1Exploit Tool / Code · 2026-06-27: 1Active Exploitation · 2026-06-27: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-06-24: 1Technical Details · 2026-06-27: 106-2406-27
Signal classification1 categories
Exploit
3100.0%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-06-242
Exploit2
2026-06-271
Exploit1
Full discourse3 posts
  • starlabs@starlabs_sg
    Exploit

    Our co-worker, @MochiNishimiya gave his intern, @peter_clowncs a patched & well-documented bug and with constraints: no NtQuery*, no PreviousMode. This is what the intern did. CVE-2023-36802, exploited a different way. https://starlabs.sg/blog/2026/06-old-bug-harder-rules-exploiting-cve-2023-36802-without-the-usual-shortcuts/

    Post summary

    The tweet points readers to a blog post detailing a novel exploitation technique for CVE‑2023‑36802, but offers no detailed technical guide, patch info, or evidence of active attacks.

    021067295.6K
    10.2K followersView on X
  • Autumn Good@autumn_good_35
    Exploit

    相変わらずインターンに求める課題のレベル高いですね Old Bug, Harder Rules : Exploiting CVE-2023-36802 Without the Usual Shortcuts https://starlabs.sg/blog/2026/06-old-bug-harder-rules-exploiting-cve-2023-36802-without-the-usual-shortcuts/

    Post summary

    The blog post focuses on a detailed exploitation technique for CVE-2023-36802, likely presenting a PoC or advanced method, but does not discuss active attacks, patches, or debunking.

    111211.2K
    7.0K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (June 1-26, 2026) http://www.cyberpocket.org 1⃣. Old Bug, Harder Rules: Exploiting CVE-2023-36802 Without the Usual Shortcuts https://starlabs.sg/blog/2026/06-old-bug-harder-rules-exploiting-cve-2023-36802-without-the-usual-shortcuts // Type confusion bug in Microsoft’s Streaming Service 2⃣. Dissecting and Exploiting Linux LPE Variant: DirtyClone (CVE-2026-43503) https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503 // CVE-2026-43503 https://github.com/rafaeldtinoco/security/tree/main/exploits/dirtyclone is a workaround for Dirty Frag vulnerability in xfrm-ESP module, which is used to accelerate encryption operations in IPsec using ESP 3⃣. Patch the Planet: a Daybreak initiative to support open source maintainers https://openai.com/index/patch-the-planet 4⃣. StrikeShark malware loader https://securelist.com/strikeshark-campaign/120326 // malware loader used in StrikeShark campaign to deploy Cobalt Strike Beacons via DLL hijacking and encrypted stages 5⃣. NGINX ngx_http_v3_module vulnerability https://my.f5.com/manage/s/article/K000161616 // CVE-2026-42530 https://github.com/0xBlackash/CVE-2026-42530 6⃣. BOD 26-04: Prioritizing Security Updates Based on Risk https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk 7⃣. AMD will reinstate memory encryption on Ryzen 9000 CPUs through a BIOS update in July https://www.tomshardware.com/pc-components/cpus/amd-will-reinstate-memory-encryption-on-ryzen-9000-cpus-through-a-bios-update-in-july-tsme-is-coming-back-after-valuable-community-feedback 8⃣. libssh2 vulnerabilities https://www.secure-iss.com/newsroom/libssh2-critical-vulnerabilities-rce-dos // Out-of-Bounds Write via Unchecked packet_length in transport.c (CVE-2026-55200, CVE-2026-55199) 9⃣. HallWatch user mode detector https://github.com/Zypherion-Technologies/HallWatch // Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, VEH syscalls & more 🔟  AI SOC Evaluation Framework https://secops-unpacked.ai/asef/guide

    Post summary

    The post catalogs several CVEs, providing direct links to PoC code and exploit details, notes real-world exploitation via the StrikeShark loader, and mentions available workarounds or patches.

    00001319
    3.3K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1809--arm64
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---

Explore more