CVE-2023-36046HighCVSS 7.1

Windows Authentication Denial of Service Vulnerability

Published
November 14, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metrics, successful exploitation of this vulnerability does not impact confidentiality (C:N) but has major impact on integrity (I:H) and availability (A:H). What does that mean for this vulnerability? An attacker who successfully exploits this vulnerability cannot access existing files (C:N) but can write or overwrite file contents (I:H), which potentially may cause the system to become unavailable (A:H).

🎯 Affected products7

  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 23H2 for ARM64-based Systems
  • Windows 11 Version 23H2 for x64-based Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022, 23H2 Edition (Server Core installation)

✅ Remediation

KB5032192 (Security Update) — fixed build 10.0.22000.2600 KB5032190 (Security Update) — fixed build 10.0.22621.2715 KB5032190 (Security Update) — fixed build 10.0.22631.2715 KB5032202 (Security Update) — fixed build 10.0.25398.531

🔗 References (7)