CVE-2023-21803CriticalCVSS 9.8

Windows iSCSI Discovery Service Remote Code Execution Vulnerability

Published
February 14, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit the vulnerability? An attacker could exploit the vulnerability by sending a specially crafted malicious DHCP discovery request to the iSCSI Discovery Service on 32-bit machines. An attacker who successfully exploited the vulnerability could then gain the ability to execute code on the target system.

🎯 Affected products8

  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 Version 1809 for 32-bit Systems
  • Windows 10 Version 20H2 for 32-bit Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 for 32-bit Systems
  • Windows Server 2008 for 32-bit Systems Service Pack 2
  • Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

✅ Remediation

KB5022840 (Security Update) — fixed build 10.0.17763.4010 KB5022834 (Security Update) — fixed build 10.0.19042.2604 KB5022834 (Security Update) — fixed build 10.0.19044.2604 KB5022834 (Security Update) — fixed build 10.0.19045.2604 KB5022858 (Security Update) — fixed build 10.0.10240.19747 KB5022838 (Security Update) — fixed build 10.0.14393.5717 KB5022890 (Monthly Rollup) — fixed build 6.0.6003.21915 KB5022893 (Security Only) — fixed build 6.0.6003.21915

🔗 References (13)