CVE-2023-38171HighCVSS 7.5

Microsoft QUIC Denial of Service Vulnerability

Published
October 10, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Where can I find more information? Please see the GitHub Advisory relating to this vulnerability here: https://github.com/microsoft/msquic/security/advisories/GHSA-xh5m-8qqp-c5x7#event-111621

🎯 Affected products12

  • .NET 7.0
  • Microsoft Visual Studio 2022 version 17.2
  • Microsoft Visual Studio 2022 version 17.4
  • Microsoft Visual Studio 2022 version 17.6
  • Microsoft Visual Studio 2022 version 17.7
  • PowerShell 7.3
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)

✅ Remediation

KBRelease Notes (Security Update) — fixed build 17.2.21 KBRelease Notes (Security Update) — fixed build 17.4.13 KBRelease Notes (Security Update) — fixed build 17.6.9 KBRelease Notes (Security Update) — fixed build 17.7.6 KB5031364 (Security Update) — fixed build 10.0.20348.2031 KB5031358 (Security Update) — fixed build 10.0.22000.2538 KB5031354 (Security Update) — fixed build 10.0.22621.2428 KB5032875 (Security Update) — fixed build 7.0.13 KBRelease Notes (Security Update) — fixed build 7.3.9

🔗 References (17)