{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3omicrosoftwindows_1122h2arm64/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:microsoft:windows_11:21h2:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_11:21h2:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_11:22h2:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_11:22h2:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2023-21768"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows 11","Windows Server 2022","Windows Ancillary Function Driver For Winsock"],"_cs_severities":["high"],"_cs_tags":["windows","privilege-escalation","cve"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eCVE-2023-21768 is a local privilege escalation (LPE) vulnerability affecting the Ancillary Function Driver (AFD) for Winsock on various Microsoft Windows versions. The vulnerability allows an attacker with low-level privileges to interact with the AFD driver to elevate an arbitrary process to SYSTEM privileges. Recent activity on exploit repositories has seen a surge in publicly available proof-of-concept (PoC) code targeting this flaw. These tools typically take a process identifier (PID) as an argument to perform the elevation. Defenders should prioritize patching vulnerable systems, as the existence of weaponized PoCs significantly reduces the barrier to exploitation for an adversary already established on an endpoint.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2023-21768 allows a low-privileged user to gain full administrative control (SYSTEM) over the host operating system. This impact is significant in multi-user environments, corporate workstations, and server infrastructure where unauthorized privilege escalation can lead to full system compromise, credential dumping, and persistence. Given the availability of functional PoC binaries, the likelihood of this vulnerability being used in post-exploitation activities is elevated.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize patching Windows 11 and Windows Server 2022 systems by applying the latest cumulative security updates from Microsoft.\u003c/li\u003e\n\u003cli\u003eMonitor process-creation logs for the execution of unrecognized binaries that accept PID arguments and interact with system processes.\u003c/li\u003e\n\u003cli\u003eRestrict the ability of non-administrative users to run arbitrary or untrusted binaries on sensitive servers.\u003c/li\u003e\n\u003cli\u003eReview endpoint telemetry for suspicious parent-child process relationships where a low-privilege process attempts to interact with high-integrity system components.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T13:04:36Z","date_published":"2026-08-26T13:04:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2023-21768-poc/","summary":"Public availability of multiple proof-of-concept exploits for CVE-2023-21768, a local privilege escalation vulnerability in the Windows Ancillary Function Driver (AFD), increases the risk of local users elevating processes to SYSTEM privileges.","title":"Public Proof-of-Concept for CVE-2023-21768 Local Privilege Escalation","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2023-21768-poc/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:microsoft:windows_11:22h2:*:*:*:*:*:arm64:*","version":"https://jsonfeed.org/version/1.1"}