CVE-2023-28234HighCVSS 7.5
Windows Secure Channel Denial of Service Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Does this vulnerability affect all versions of TLS? No. Only those devices running TLS 1.3 are affected. For more information on supported TLS implementations please visit: https://learn.microsoft.com/en-us/windows/win32/secauthn/protocols-in-tls-ssl--schannel-ssp-
🎯 Affected products6
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
✅ Remediation
KB5025230 (Security Update) — fixed build 10.0.20348.1668 KB5025224 (Security Update) — fixed build 10.0.22000.1817 KB5025239 (Security Update) — fixed build 10.0.22621.1555
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28234
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025230
- referencehttps://support.microsoft.com/help/5025230
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025224
- referencehttps://support.microsoft.com/help/5025224
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025239
- referencehttps://support.microsoft.com/help/5025239