CVE-2023-24941CriticalCVSS 9.8
Windows Network File System Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? This vulnerability could be exploited over the network by making an unauthenticated, specially crafted call to a Network File System (NFS) service to trigger a Remote Code Execution (RCE).
🎯 Affected products10
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
✅ Remediation
KB5026362 (Security Update) — fixed build 10.0.17763.4377 KB5026370 (Security Update) — fixed build 10.0.20348.1726 KB5026456 (Security Hotpatch Update) — fixed build 10.0.20348.1724 KB5026363 (Security Update) — fixed build 10.0.14393.5921 KB5026419 (Monthly Rollup) — fixed build 6.2.9200.24266 KB5026411 (Security Only) — fixed build 6.2.9200.24266 KB5026415 (Monthly Rollup) — fixed build 6.3.9600.20969 KB5026409 (Security Only) — fixed build 6.3.9600.20969
🔗 References (17)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24941
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5026362
- referencehttps://support.microsoft.com/help/5026362
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5026370
- referencehttps://support.microsoft.com/help/5026370
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5026456
- referencehttps://support.microsoft.com/help/5026456
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5026363
- referencehttps://support.microsoft.com/help/5026363
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5026419
- referencehttps://support.microsoft.com/help/5026419
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5026411
- referencehttps://support.microsoft.com/help/5026411
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5026415
- referencehttps://support.microsoft.com/help/5026415
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5026409
- referencehttps://support.microsoft.com/help/5026409