CVE-2023-35643HighCVSS 7.5
DHCP Server Service Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is remote heap memory.
🎯 Affected products11
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
- Windows Server 2022, 23H2 Edition (Server Core installation)
✅ Remediation
KB5033371 (Security Update) — fixed build 10.0.17763.5206 KB5033118 (Security Update) — fixed build 10.0.20348.2159 KB5033464 (Security Hotpatch Update) — fixed build 10.0.20348.2144 KB5033383 (Security Update) — fixed build 10.0.25398.584 KB5033373 (Security Update) — fixed build 10.0.14393.6529 KB5033429 (Monthly Rollup) — fixed build 6.2.9200.24614 KB5033420 (Monthly Rollup) — fixed build 6.3.9600.21715
🔗 References (9)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35643
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033371
- referencehttps://support.microsoft.com/help/5033371
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033118
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033464
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033383
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033373
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033429
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5033420