Windows iSCSI Discovery Service Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit the vulnerability? An attacker could exploit the vulnerability by sending a specially crafted malicious DHCP discovery request to the iSCSI Discovery Service on 32-bit machines. An attacker who successfully exploited the vulnerability could then gain the ability to execute code on the target system.
🎯 Affected products8
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 22H2 for 32-bit Systems
- Windows 10 for 32-bit Systems
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
✅ Remediation
KB5022840 (Security Update) — fixed build 10.0.17763.4010 KB5022834 (Security Update) — fixed build 10.0.19042.2604 KB5022834 (Security Update) — fixed build 10.0.19044.2604 KB5022834 (Security Update) — fixed build 10.0.19045.2604 KB5022858 (Security Update) — fixed build 10.0.10240.19747 KB5022838 (Security Update) — fixed build 10.0.14393.5717 KB5022890 (Monthly Rollup) — fixed build 6.0.6003.21915 KB5022893 (Security Only) — fixed build 6.0.6003.21915
🔗 References (13)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21803
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022840
- referencehttps://support.microsoft.com/help/5022840
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022834
- referencehttps://support.microsoft.com/help/5022834
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022858
- referencehttps://support.microsoft.com/help/5022858
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022838
- referencehttps://support.microsoft.com/help/5022838
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022890
- referencehttps://support.microsoft.com/help/5022890
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022893
- referencehttps://support.microsoft.com/help/5022893