<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:microsoft:windows_11:21h2:*:*:*:*:*:x64:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3omicrosoftwindows_1121h2x64/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 26 Aug 2026 13:04:36 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3omicrosoftwindows_1121h2x64/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Public Proof-of-Concept for CVE-2023-21768 Local Privilege Escalation</title><link>https://feed.craftedsignal.io/briefs/2026-08-cve-2023-21768-poc/</link><pubDate>Wed, 26 Aug 2026 13:04:36 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-cve-2023-21768-poc/</guid><description>Public availability of multiple proof-of-concept exploits for CVE-2023-21768, a local privilege escalation vulnerability in the Windows Ancillary Function Driver (AFD), increases the risk of local users elevating processes to SYSTEM privileges.</description><content:encoded><![CDATA[<p>CVE-2023-21768 is a local privilege escalation (LPE) vulnerability affecting the Ancillary Function Driver (AFD) for Winsock on various Microsoft Windows versions. The vulnerability allows an attacker with low-level privileges to interact with the AFD driver to elevate an arbitrary process to SYSTEM privileges. Recent activity on exploit repositories has seen a surge in publicly available proof-of-concept (PoC) code targeting this flaw. These tools typically take a process identifier (PID) as an argument to perform the elevation. Defenders should prioritize patching vulnerable systems, as the existence of weaponized PoCs significantly reduces the barrier to exploitation for an adversary already established on an endpoint.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2023-21768 allows a low-privileged user to gain full administrative control (SYSTEM) over the host operating system. This impact is significant in multi-user environments, corporate workstations, and server infrastructure where unauthorized privilege escalation can lead to full system compromise, credential dumping, and persistence. Given the availability of functional PoC binaries, the likelihood of this vulnerability being used in post-exploitation activities is elevated.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Prioritize patching Windows 11 and Windows Server 2022 systems by applying the latest cumulative security updates from Microsoft.</li>
<li>Monitor process-creation logs for the execution of unrecognized binaries that accept PID arguments and interact with system processes.</li>
<li>Restrict the ability of non-administrative users to run arbitrary or untrusted binaries on sensitive servers.</li>
<li>Review endpoint telemetry for suspicious parent-child process relationships where a low-privilege process attempts to interact with high-integrity system components.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>windows</category><category>privilege-escalation</category><category>cve</category></item></channel></rss>