CVE-2023-32021HighCVSS 7.1

Windows SMB Witness Service Security Feature Bypass Vulnerability

Published
June 13, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What kind of security feature could be bypassed by successfully exploiting this vulnerability? An attacker who successfully exploited this vulnerability could execute RPC procedures that are restricted to privileged accounts, bypassing the access check for the RPC procedures.

How could an attacker exploit the vulnerability? To exploit this vulnerability, an attacker could execute a specially crafted malicious script which executes an RPC call to a Windows SMB Witness Service.

🎯 Affected products8

  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)

✅ Remediation

KB5027222 (Security Update) — fixed build 10.0.17763.4499 KB5027225 (Security Update) — fixed build 10.0.20348.1787 KB5027319 (Security Hotpatch Update) — fixed build 10.0.20348.1784 KB5027219 (Security Update) — fixed build 10.0.14393.5989 KB5027271 (Monthly Rollup) — fixed build 6.3.9600.21013 KB5027282 (Security Only) — fixed build 6.3.9600.21013

🔗 References (13)