October 4, 2023 · Applied Cybernetics Group
CVE-2023-28229 — Microsoft Windows CNG Key Isolation Service
Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
- Added to KEV
2023-10-04- Federal due date
2023-10-25- Vendor
- Microsoft
- Product
- Windows CNG Key Isolation Service
- EPSS
- 92.6th percentile (score 0.086, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2023-28229
CISA short description
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.