CVE-2023-21823
Microsoft Windows Graphic Component Privilege Escalation Vulnerability
CVSS
7.8
High
EPSS
5.6%
p92
KEV
YES
Feb 14, 2023
Exploit Today
78
0-100
Published: Feb 14, 2023 · Last modified: Aug 19, 2026 · CWE-190
5.6%EPSS · 30 days5.6%
2026-08-022026-08-31
Product
Microsoft / Windows
Vulnerability
Microsoft Windows Graphic Component Privilege Escalation Vulnerability
Added to KEV
Feb 14, 2023
Remediate by
Mar 7, 2023
Known ransomware use
No
Summary description
Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.
Required action
Apply updates per vendor instructions.
Notes
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21823; https://nvd.nist.gov/vuln/detail/CVE-2023-21823
Windows Graphics Component Remote Code Execution Vulnerability
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-547559.6 CRI31.6%
——9Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/kapp/kda/trigger.go sum those values in uint32 accumulators. Crafted values such as two 0x80000000 entries wrap the validation sum to zero and pass CheckValid100Params. Royalty payout paths in core/kapp/accounts/accounts.go, core/kapp/market/market.go, and core/kapp/ito/ito.go then credit each oversized split amount and silently discard a negative remainder, allowing ordinary asset transfers, marketplace purchases, or ITO purchases to create unbacked KLV or other assets. This issue is fixed in version 1.7.19.3dCVE-2026-19313—38.9%
——12An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.3dCVE-2026-383507.5 HIG24.9%
——7An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.3dCVE-2026-383497.5 HIG24.9%
——7An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.3dCVE-2026-383487.5 HIG24.9%
——7An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.3dCVE-2026-383467.5 HIG24.9%
——7An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.3d