QID 92012
Date Published: 2023-05-10
QID 92012: Microsoft Windows Sysmon Elevation of Privilege Vulnerability for May 2023
System Monitor (Sysmon) is a Windows system service and device driver that, once installed on a system, remains resident across system reboots to monitor and log system activity to the Windows event log
Affected Software
Sysmon prior to version 14.16.0.0
QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Sysmon.exe
Successful exploit could lead to elevation of privileges
Solution
Customers are advised to refer to CVE-2023-29343 for more details pertaining to this vulnerability.
Vendor References
- CVE-2023-29343 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-29343
CVEs related to QID 92012
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-29343 |
|