CVE-2023-21676HighCVSS 8.8
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? This vulnerability could be exploited over the network by an authenticated attacker through a low complexity attack on a server configured as the domain controller.
🎯 Affected products19
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 Version 22H2 for 32-bit Systems
- Windows 10 Version 22H2 for ARM64-based Systems
- Windows 10 Version 22H2 for x64-based Systems
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
✅ Remediation
KB5022286 (Security Update) — fixed build 10.0.17763.3887 KB5022291 (Security Update) — fixed build 10.0.20348.1487 KB5022282 (Security Update) — fixed build 10.0.19042.2486 KB5022287 (Security Update) — fixed build 10.0.22000.1455 KB5022282 (Security Update) — fixed build 10.0.19044.2486 KB5022303 (Security Update) — fixed build 10.0.22621.1105 KB5022282 (Security Update) — fixed build 10.0.19045.2486
🔗 References (9)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21676
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022286
- referencehttps://support.microsoft.com/help/5022286
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022291
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022282
- referencehttps://support.microsoft.com/help/5022282
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022287
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022303
- referencehttps://support.microsoft.com/help/5022303