CVE-2023-21759HighCVSS 3.3

Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability

Published
January 10, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What kind of security feature could be bypassed by successfully exploiting this vulnerability? An attacker who successfully exploited this vulnerability could bypass the Fast Identity Online (FIDO) secure authentication feature.

🎯 Affected products14

  • Windows 10 Version 20H2 for 32-bit Systems
  • Windows 10 Version 20H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)

✅ Remediation

KB5022282 (Security Update) — fixed build 10.0.19045.2486 KB5022303 (Security Update) — fixed build 10.0.22621.1105 KB5022291 (Security Update) — fixed build 10.0.20348.1487 KB5022287 (Security Update) — fixed build 10.0.22000.1455 KB5022282 (Security Update) — fixed build 10.0.19044.2486 KB5022282 (Security Update) — fixed build 10.0.19042.2486

🔗 References (7)