CVE-2023-21674 is a use-after-free vulnerability in the Windows NT kernel's Advanced Local Procedure Call (ALPC) handling. A deferred ALPC send issued through NtWaitForWorkViaWorkerFactory can specify the synchronous-request flag. This causes ALPC to retain a pointer to the sending thread in the message's WaitingThread field. If the sending thread terminates before ALPC cleanup, the retained pointer references a freed ETHREAD object. Subsequent ALPC cancellation or cleanup can dereference that dangling pointer. The flaw was exploited in the wild and was used in a Chrome sandbox-escape exploit chain.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (POC) exploit for CVE-2023-21674, a Use-After-Free (UAF) vulnerability in the Windows Advanced Local Procedure Call (ALPC) subsystem. The exploit is implemented in a single C++ file (CVE-2023-21674.cpp) and is designed to be run locally on a vulnerable Windows 10 system. The code creates and manipulates ALPC ports, private namespaces, IO completion objects, and worker factories to trigger the UAF condition. The final step involves impersonating a client via NtAlpcImpersonateClientOfPort, which can result in privilege escalation to SYSTEM. The README provides context about the vulnerability, including crash dumps and debugging output, confirming the exploit's effect. No network endpoints are involved; all actions are performed locally via Windows kernel APIs. The repository is structured simply, with the exploit code and a detailed README.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously addressed and weaponized zero-day vulnerability mentioned solely as historical comparison for CVE-2026-85880.
A previously resolved Windows ALPC zero-day mentioned only for historical context.
A previously exploited Windows ALPC zero-day referenced as historical comparison.
A local privilege escalation vulnerability in Microsoft Windows, allowing attackers to gain elevated privileges on a compromised system.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.