Microsoft Remote Registry Service Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
How could an attacker exploit this vulnerability? A remote, authenticated attacker who is on the domain could exploit an out of bounds write vulnerability within regsvc to execute arbitrary code on the server.
🎯 Affected products36
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 Version 22H2 for 32-bit Systems
- Windows 10 Version 22H2 for ARM64-based Systems
- Windows 10 Version 22H2 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 Version 23H2 for ARM64-based Systems
- Windows 11 Version 23H2 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2016
- +6 more not shown
✅ Remediation
KB5032196 (Security Update) — fixed build 10.0.17763.5122 KB5032198 (Security Update) — fixed build 10.0.20348.2113 KB5032304 (SecurityHotpatchUpdate) — fixed build 10.0.20348.2091 KB5032192 (Security Update) — fixed build 10.0.22000.2600 KB5032189 (Security Update) — fixed build 10.0.19043.3693 KB5032190 (Security Update) — fixed build 10.0.22621.2715 KB5032189 (Security Update) — fixed build 10.0.19045.3693 KB5032190 (Security Update) — fixed build 10.0.22631.2715 KB5032202 (Security Update) — fixed build 10.0.25398.531 KB5032199 (Security Update) — fixed build 10.0.10240.20308 KB5032197 (Security Update) — fixed build 10.0.14393.6452 KB5032254 (Monthly Rollup) — fixed build 6.0.6003.22367 KB5032248 (Security Only) — fixed build 6.0.6003.22367 KB5032252 (Monthly Rollup) — fixed build 6.1.7601.26816 KB5032250 (Security Only) — fixed build 6.1.7601.26816 KB5032247 (Monthly Rollup) — fixed build 6.2.9200.24569 KB5032249 (Monthly Rollup) — fixed build 6.3.9600.21668
🔗 References (31)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36423
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032196
- referencehttps://support.microsoft.com/help/5032196
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032198
- referencehttps://support.microsoft.com/help/5032198
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032304
- referencehttps://support.microsoft.com/help/5032304
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032192
- referencehttps://support.microsoft.com/help/5032192
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032189
- referencehttps://support.microsoft.com/help/5032189
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032190
- referencehttps://support.microsoft.com/help/5032190
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032202
- referencehttps://support.microsoft.com/help/5032202
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032199
- referencehttps://support.microsoft.com/help/5032199
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032197
- referencehttps://support.microsoft.com/help/5032197
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032254
- referencehttps://support.microsoft.com/help/5032254
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032248
- referencehttps://support.microsoft.com/help/5032248
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032252
- referencehttps://support.microsoft.com/help/5032252
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032250
- referencehttps://support.microsoft.com/help/5032250
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032247
- referencehttps://support.microsoft.com/help/5032247
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5032249
- referencehttps://support.microsoft.com/help/5032249