A local elevation of privilege vulnerability in Microsoft Windows XAML Diagnostics. Successful exploitation allows an attacker to elevate privileges on a vulnerable Windows system. Public references identify the issue as affecting Windows and classify it as an elevation of privilege flaw, but the available information does not provide sufficient technical detail about the specific vulnerable component, function, or root cause to determine a precise weakness classification.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a proof-of-concept (POC) exploit for CVE-2023-36003, a privilege escalation vulnerability in the Windows XAML diagnostics API. The repository contains two main C++ projects: a DLL ('pe-poc-dll') and an executable ('pe-poc'). The DLL implements a COM object that, when loaded into a target process, spawns a command shell (cmd.exe) with the privileges of that process. The executable locates an inaccessible (e.g., elevated) process and injects the DLL using the XAML diagnostics API by calling the 'InitializeXamlDiagnosticsEx' function from 'Windows.UI.Xaml.dll'. The exploit can be run with a specific process ID or will automatically search for a suitable target. The code is a functional POC and does not include weaponization or automation for mass exploitation. The main attack vector is local privilege escalation on Windows systems vulnerable to CVE-2023-36003.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.