CVE-2023-36004HighCVSS 7.5

Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability

Published
December 12, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? The attacker must inject themselves into the logical network path between the target and the resource requested by the victim to read or modify network communications. This is called a machine-in-the-middle (MITM) attack.

According to the CVSS metric, user interaction is required (UI:R) and privileges required are none (PR:N). What does that mean for this vulnerability? An unauthorized attacker must wait for a user to initiate a connection.

What is the attack vector for this vulnerability? To exploit this vulnerability, an attacker would need to launch a machine-in-the-middle (MITM) attack against the traffic passing between a domain controller and the target machine.

🎯 Affected products36

  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 Version 1607 for x64-based Systems
  • Windows 10 Version 1809 for 32-bit Systems
  • Windows 10 Version 1809 for ARM64-based Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 10 for 32-bit Systems
  • Windows 10 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 23H2 for ARM64-based Systems
  • Windows 11 Version 23H2 for x64-based Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Windows Server 2008 for 32-bit Systems Service Pack 2
  • Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
  • Windows Server 2008 for x64-based Systems Service Pack 2
  • Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
  • Windows Server 2012
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2016
  • +6 more not shown

✅ Remediation

KB5033371 (Security Update) — fixed build 10.0.17763.5206 KB5033118 (Security Update) — fixed build 10.0.20348.2159 KB5033464 (Security Hotpatch Update) — fixed build 10.0.20348.2144 KB5033369 (Security Update) — fixed build 10.0.22000.2652 KB5033372 (Security Update) — fixed build 10.0.19041.3803 KB5033375 (Security Update) — fixed build 10.0.22621.2861 KB5033372 (Security Update) — fixed build 10.0.19045.3803 KB5033375 (Security Update) — fixed build 10.0.22631.2861 KB5033383 (Security Update) — fixed build 10.0.25398.584 KB5033379 (Security Update) — fixed build 10.0.10240.20345 KB5033373 (Security Update) — fixed build 10.0.14393.6529 KB5033422 (Monthly Rollup) — fixed build 6.0.6003.22413 KB5033427 (Security Only) — fixed build 6.0.6003.22413 KB5033433 (Monthly Rollup) — fixed build 6.1.7601.26864 KB5033424 (Security Only) — fixed build 6.1.7601.26864 KB5033429 (Monthly Rollup) — fixed build 6.2.9200.24614 KB5033420 (Monthly Rollup) — fixed build 6.3.9600.21715

🔗 References (24)