CVE-2023-38146HighCVSS 8.8
Windows Themes Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? An attacker would need to convince a targeted user to load a Windows Themes file on a vulnerable system with access to an attacker-controlled SMB share.
🎯 Affected products4
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
✅ Remediation
KB5030217 (Security Update) — fixed build 10.0.22000.2416 KB5030219 (Security Update) — fixed build 10.0.22621.2283
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38146
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5030217
- referencehttps://support.microsoft.com/help/5030217
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5030219
- referencehttps://support.microsoft.com/help/5030219