CVE-2023-35357: Windows 10 1607 Out-of-Bounds Read (CVSS 7.8)

CVE-2023-35357 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Windows Kernel Elevation of Privilege Vulnerability. EPSS estimates a 0.83% chance of exploitation in the next 30 days.

Description

Windows Kernel Elevation of Privilege Vulnerability

Metrics

CVSS 3.1 7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability 0.83%

53.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Vendor Product Versions
Microsoft Windows 10 1607 < 10.0.14393.6085
Microsoft Windows 10 1809 < 10.0.17763.4645
Microsoft Windows 10 21h2 < 10.0.19041.3208
Microsoft Windows 10 22h2 < 10.0.19045.3208
Microsoft Windows 11 21h2 < 10.0.22000.2176
Microsoft Windows 11 22h2 < 10.0.22621.1992
Microsoft Windows Server 2016 All versions
Microsoft Windows Server 2019 All versions
Microsoft Windows Server 2022 All versions

References

Timeline

Published Jul 11, 2023

Last Modified Jun 17, 2026

Status Modified

Frequently Asked Questions

What is CVE-2023-35357?

Windows Kernel Elevation of Privilege Vulnerability

How severe is CVE-2023-35357?

CVE-2023-35357 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.83% probability of exploitation in the next 30 days.

How do I fix CVE-2023-35357?

Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.