PT-2023-1772 · Microsoft · Windows

CVE-2023-21708

·

Publicado

2023-03-14

·

Atualizado

2024-05-29

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows versions prior to the fixed version
Description The issue exists due to insufficient input validation in the Procedure Call Runtime of Windows operating systems. This allows a remote attacker to execute arbitrary code.
Recommendations For Windows versions prior to the fixed version, apply the necessary patch or update to resolve the issue. As a temporary workaround, consider restricting access to the Remote Procedure Call Runtime to minimize the risk of exploitation.

Correção

RCE

Integer Underflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01367
CVE-2023-21708

Produtos afetados

Windows