CVE-2023-36046HighCVSS 7.1
Windows Authentication Denial of Service Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metrics, successful exploitation of this vulnerability does not impact confidentiality (C:N) but has major impact on integrity (I:H) and availability (A:H). What does that mean for this vulnerability? An attacker who successfully exploits this vulnerability cannot access existing files (C:N) but can write or overwrite file contents (I:H), which potentially may cause the system to become unavailable (A:H).
🎯 Affected products7
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 Version 23H2 for ARM64-based Systems
- Windows 11 Version 23H2 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2022, 23H2 Edition (Server Core installation)
✅ Remediation
KB5032192 (Security Update) — fixed build 10.0.22000.2600 KB5032190 (Security Update) — fixed build 10.0.22621.2715 KB5032190 (Security Update) — fixed build 10.0.22631.2715 KB5032202 (Security Update) — fixed build 10.0.25398.531
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36046
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032192
- referencehttps://support.microsoft.com/help/5032192
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032190
- referencehttps://support.microsoft.com/help/5032190
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032202
- referencehttps://support.microsoft.com/help/5032202